handoff

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL-setup.md

The reviewed fragment is a detailed and potentially dangerous automation flow intended for legitimate setup. It lacks sufficient safeguards around input validation, error handling, and state integrity. While not overtly malicious, the design concentrates high-risk operations (secret generation, external deployments, and credential persistence) that require strong safeguards and tamper-evident controls. Suggested improvements include explicit validation, clearer failure modes, separated deployment actions from configuration persistence, and hardened logging and access controls.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:41 PM
Package URL
pkg:socket/skills-sh/dinghaoz%2Fskills%2Fhandoff%2F@54944323da651b5e138ea16710a0d82eb52593e7