executing-subtask

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow is broadly consistent with a Jira subtask execution skill, but it relies on an unspecified `agent` executable and a delegated subagent with code-writing/test-running authority. No clear credential theft or malicious exfiltration is present, yet the unverifiable CLI requirement and agent delegation keep overall risk high.

Confidence: 79%Severity: 72%
Audit Metadata
Analyzed At
Mar 26, 2026, 08:41 PM
Package URL
pkg:socket/skills-sh/b-mendoza%2Fagent-skills%2Fexecuting-subtask%2F@f8bf1e3d1e26009024d925be96bd4352d5beab4e