god
Warn
Audited by Socket on May 6, 2026
1 alert found:
AnomalyAnomalysub-skills/pack-up/SKILL.md
LOWAnomalyLOW
sub-skills/pack-up/SKILL.md
SUSPICIOUS. The core commit/push/PR behavior fits the stated purpose of a pack-up skill, and data flows mostly align with GitHub/dev tooling. However, the skill grants broad execution and can autonomously perform external publishing actions, and its natural-language hooks materially expand scope by allowing arbitrary command execution from a local file. That makes it coherent but medium-risk rather than benign.
Confidence: 86%Severity: 61%
Audit Metadata