executing-subtask
Warn
Audited by Socket on Mar 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow is broadly consistent with a Jira subtask execution skill, but it relies on an unspecified `agent` executable and a delegated subagent with code-writing/test-running authority. No clear credential theft or malicious exfiltration is present, yet the unverifiable CLI requirement and agent delegation keep overall risk high.
Confidence: 79%Severity: 72%
Audit Metadata