langchain-bmad

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent as a framework/workflow guide and uses apparently legitimate install sources, but it instructs transitive installation of other skills—including a wildcard load—which expands agent trust beyond this skill’s own scope. No credential harvesting, exfiltration, or deceptive data flow is evident, so this is not malicious; the main concern is medium supply-chain/transitive-trust risk.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Mar 23, 2026, 02:02 PM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-gods%2Flangchain-bmad%2F@c97eac5f0c6f87c1857f7746a2e84cb8c4a1cb44