arch-council
Warn
Audited by Socket on Mar 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core debate/orchestration purpose matches the stated capability, and the CLI dependencies appear to be official. Risk comes from sending potentially sensitive multi-repo context to external model providers, processing untrusted repo content with prompt-injection exposure, and the optional skill self-update trust chain via `npx skills update`.
Confidence: 85%Severity: 63%
Audit Metadata