twd

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The TWD agent fragment corresponds to a legitimate, self-contained local testing workflow with explicit DEV guards and localhost isolation. The main risks are operational (test manipulation during fix loops) and supply-chain risk from external tooling (npm/npx). No malicious data flows or credential theft are evident. Recommended improvements focus on tightening final-run guarantees (remove all it.only() before full suite) and implementing verifiable integrity checks for installed tooling (e.g., lockfiles, SHASUM verification).

Confidence: 78%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 10:23 PM
Package URL
pkg:socket/skills-sh/BRIKEV%2Ftwd-ai%2Ftwd%2F@77a14a833be3fbfc220a916dbed24eb6c9959625