discover-tasks

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment appears to be a legitimate utility for aggregating and prioritizing tasks from multiple sources in a software-project workflow. It orchestrates external CLIs (GitHub/GitLab), local markdown task lists, and a custom source, filters, scores, and presents choices to the user, then updates internal state. There are no hardcoded secrets, suspicious external endpoints, or data exfiltration patterns visible in the fragment. The primary security considerations relate to proper handling of tokens/credentials by the underlying CLI tools (GitHub/GitLab) and ensuring temporary files are cleaned up and access-controlled. Overall, the footprint is coherent with its stated purpose and reasonably scoped; risk is moderate (due to external tool usage and file-based interim storage) but not inherently malicious.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 12:30 AM
Package URL
pkg:socket/skills-sh/avifenesh%2Fagentsys%2Fdiscover-tasks%2F@6dc94778bfc406f678e96e5aac8e3a701ec8ef87