skill-editor
Audited by Socket on Mar 1, 2026
1 alert found:
SecurityThe code fragment describes a high-complexity orchestration framework for editing Claude Code skills, with explicit phase gating, agent delegation, and integration with local repo tooling. There are no evident malicious behaviors such as credential harvesting, unauthorized exfiltration, or remote command execution within the fragment. The footprint is coherent with the stated purpose of coordinating structured multi-agent reviews and safe execution, though the substantial orchestration surface and reliance on multiple tools introduce operational risk and potential for misconfiguration. Overall, the skill appears benign in intent but warrants careful access control and monitoring given its powerful coordination capabilities.