preen
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe preen skill acts as a coherent meta-automation layer coordinating internal sub-skills, with stateful rotation and PR-driven improvements. Its footprint is proportionate to its stated purpose: it relies on local state, standard development tooling, and GitHub-based PR workflows. No credential harvesting, unverifiable binaries, or external data exfiltration patterns are evident. The main concerns are related to shell-command surface area and the potential for disruptive changes if scoring/metrics misbehave, but these are mitigated by explicit guardrails and audit modes. Overall, the skill appears BENIGN with MEDIUM-level operational risk due to the complexity of automated changes in a live repo and reliance on external CLI tooling.