stask-worker
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow purpose is coherent for task orchestration, but it relies on an unverified, unpinned `npx` package and directs the agent to take autonomous external actions (git push, Slack posting, remote task updates). This looks more like a risky orchestration skill than confirmed malware.
Confidence: 82%Severity: 74%
Audit Metadata