dag-feedback-synthesizer

Warn

Audited by Socket on Feb 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] No evidence of malware or obfuscated malicious code in the provided skill. Behavior and capabilities align with its stated purpose of synthesizing and prioritizing feedback from DAG signals. The primary security consideration is the skill's permission to write/edit agent state and system prompt additions — a legitimate requirement for this role but a notable amplification of impact if misused. Recommend restricting write/edit scope and auditing downstream usages of systemPromptAdditions and any files the skill can modify. LLM verification: BENIGN DESIGN, with coherent structures for a DAG Feedback Synthesizer. The fragment functions as a specification rather than an executable module. To reduce risk in production, provide a complete runtime implementation, explicit signal source authentication, input sanitization for template outputs, and governance around automated re-execution triggers. The static scanner findings about template literals should be reviewed in the final implementation to prevent shell-like interpretation when int

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 19, 2026, 08:39 PM
Package URL
pkg:socket/skills-sh/curiositech%2Fsome_claude_skills%2Fdag-feedback-synthesizer%2F@03baa6201af1a400bdab4a1b2ed7910073678e96