elephant-build

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated software-build purpose, but it expands agent authority into installing dependencies, executing unverifiable internal CLIs, invoking other skills, and shipping code. No clear credential theft or external exfiltration is present, so this is not malicious, but it carries medium security risk due to execution trust and autonomous code-shipping behavior.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Mar 13, 2026, 11:54 PM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fgroveengine%2Felephant-build%2F@7e8ff50c34add46806be3a2438a92f2a9f812c41