summon
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s orchestration purpose broadly matches its lifecycle-management behavior, but it is a high-risk autonomous controller with broad action permissions, recursive skill delegation, untrusted GitHub-content intake, cron-based self-healing, and optional automatic PR merges. The main concern is not malware but disproportionate autonomous control and transitive trust.
Confidence: 87%Severity: 74%
Audit Metadata