quality-verify-implementation-complete

Warn

Audited by Socket on Feb 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Outbound data post or form upload via curl/wget detected All findings: [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] The analyzed fragment is a governance/verification guide that outlines best practices for ensuring code artifacts are created, wired, and executed before marking work complete. It does not contain executable code, credential handling, or external network interactions. The footprint is coherent with its stated purpose (CCV-based verification) and does not present malicious behavior by itself. Caution is advised to ensure teams actually follow the Four Questions and Phase verifications to prevent bypasses, but no security threats are evident in the fragment itself. LLM verification: This document is a legitimate verification skill that prescribes repo-local inspections, wiring checks, and runtime evidence collection to ensure implementations are integrated and executed. It contains no hard-coded secrets, obfuscated code, or direct calls to external domains. The principal security concern is procedural: the instructions encourage executing repository-provided scripts and arbitrary commands without providing provenance or explicit audit steps — executing unreviewed scripts is

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 24, 2026, 05:29 PM
Package URL
pkg:socket/skills-sh/dawiddutoit%2Fcustom-claude%2Fquality-verify-implementation-complete%2F@37b9aca55107b790439f78674e29d1ecbca57d84