fix-hard
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core bug-fixing purpose is legitimate, but the skill expands scope by dynamically activating other skills, incorporating untrusted internet research into a write-capable workflow, and enabling optional git push. This is not confirmed malware, but it carries medium risk due to transitive trust and prompt-injection exposure.
Confidence: 86%Severity: 58%
Audit Metadata