recover

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches a context-recovery skill and local file/git access is proportionate, but the optional helper CLI ecosystem introduces medium supply-chain and data-flow uncertainty. The install guidance for `ao` and `gt` does not match verified upstream docs, and the skill can forward project context to `ao` services via lookup/metrics/codex commands. This is not clearly malicious, but the dependency trust and outbound context flow are inconsistent enough to warrant caution.

Confidence: 82%Severity: 53%
Audit Metadata
Analyzed At
Apr 5, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Frecover%2F@d89b6e779d510d55f6f31bd1f9382f9a19adc546