implement
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches an implementation orchestrator, but its operational footprint is high-trust. The main concerns are autonomous code modification with bypassed permissions and transitive invocation of other skills whose behavior is not provided here. Supply-chain risk from `uv run` is limited and appears same-tool legitimate rather than malicious. No clear credential theft or exfiltration is present in this skill alone.
Confidence: 87%Severity: 68%
Audit Metadata