herdr-pm-agent

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated PM/orchestration purpose, so it does not read like credential theft or covert exfiltration. However, it grants broad cross-pane command authority, transcript access, parallel executor control, and high-autonomy operation, including a mode that can skip risky-action approval; that makes it a high-impact orchestration skill with meaningful operational risk even though the behavior is internally coherent.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 11:52 PM
Package URL
pkg:socket/skills-sh/yigitkonur%2Fherdr-pm%2Fherdr-pm-agent%2F@e0c41e9e99bfd4af0d1c3bbb11ce1bce2bdf89da435b0fb2d7e263af80359123
Security Audit — socket — herdr-pm-agent