bmad-idea
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is benign, but the installation model is a transitive third-party skill load with broader local permissions than a creativity workflow appears to need. I see no credential harvesting or exfiltration in the provided content, so this looks more like medium supply-chain/trust risk than confirmed malware.
Confidence: 85%Severity: 56%
Audit Metadata