list-tasks

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose is benign (listing tasks), but its implementation is unsafe. Directly interpolating user-controlled $ARGUMENTS into a Bash-executed command creates a high-severity command injection vulnerability. There is also medium supply-chain risk from an unverified `taskmd` binary and an excessive permission scope (Bash access). Recommend immediate remediation (avoid shell interpolation, enforce argument allowlist, restrict tooling and verify binary provenance) before running this skill in sensitive environments.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:39 PM
Package URL
pkg:socket/skills-sh/driangle%2Ftaskmd%2Flist-tasks%2F@a41df5cff5ff72c0caaa6efa9b168fc422d84074