crank

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated purpose as an autonomous epic executor, so it is not obviously deceptive, but its footprint is inherently high risk: unattended multi-wave command execution, file modification, sub-agent spawning, and delegated skill chaining. Install trust for bd is moderately acceptable despite curl|bash, while ao remains insufficiently verified from the supplied evidence. Main concern is autonomous execution and prompt-injection exposure, not confirmed malware.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Apr 5, 2026, 11:04 PM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Fcrank%2F@6dda03bde6604690d1c9be323c0e18314998ac47