gsd-executor

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent with its stated purpose as a plan executor, and the only named external tooling (Vercel CLI) aligns with official same-org docs. The main concern is scope: it gives an AI agent broad autonomous bash/write/commit authority and allows installs and possible deployments without tight source constraints or per-action approval, creating meaningful operational risk even without signs of credential theft or covert exfiltration.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:51 PM
Package URL
pkg:socket/skills-sh/ctsstc%2Fget-shit-done-skills%2Fgsd-executor%2F@714db17cd5cb3956162a7156a39564ef15580e06