summon

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s orchestration purpose broadly matches its lifecycle-management behavior, but it is a high-risk autonomous controller with broad action permissions, recursive skill delegation, untrusted GitHub-content intake, cron-based self-healing, and optional automatic PR merges. The main concern is not malware but disproportionate autonomous control and transitive trust.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:25 PM
Package URL
pkg:socket/skills-sh/athola%2Fclaude-night-market%2Fsummon%2F@2241d982eaf994db94ff76fdea83f5d18157ded1