tapestry

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Report 2 provides a coherent alignment with the stated purpose but reveals notable supply-chain and data-handling risks due to on-the-fly tool installation, multi-tool dependency, and potential non-consensual persistence of extracted data. The risk is medium-to-high for deployment without mitigations such as explicit user prompts for installations, version pinning, and data minimization/purge options. Recommend tightening control over tool installation (explicit consent, pinned versions), sandboxing/execution isolation, and clear data handling policies. Overall assessment: the concept is sound, but the current implementation details necessitate cautious deployment and stricter governance.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:10 AM
Package URL
pkg:socket/skills-sh/ajbcoding%2Fclaude-skill-eval%2Ftapestry%2F@e82867ca114c9af08ad452180355b2fde72053c7