parallel-task-spark

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a parallel development orchestrator, but it grants broad autonomous write and local commit behavior based on plan-file content that may be untrusted. No clear malware, credential theft, or external exfiltration is present, yet the combination of recursive subagent execution, repo-wide edits, and automatic commits creates meaningful operational risk.

Confidence: 88%Severity: 54%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/am-will%2Fcodex-skills%2Fparallel-task-spark%2F@b1dd4b7e96d0ef85500163403e13cd1418dedc07