ooo
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose is coherent for a development workflow, but the installation story is not fully consistent: the declared source is Q00/ouroboros while the documented skill install comes from a different repo, creating a transitive trust chain. Broad execution permissions and a persistent autonomous loop are proportionate to the workflow but still raise medium operational risk.
Confidence: 84%Severity: 76%
Audit Metadata