todo-init
Fail
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill's footprint is coherent with its stated purpose: it initializes a local per-project agent-todos configuration, creates the necessary directory structure, and updates in-repo documentation to reflect the new workflow. It remains within safe operational boundaries (no external network use or credential handling). Minor concerns include potential unsafeguarded edits to CLAUDE.md and minimal input validation for user-provided paths and values, which could be improved with explicit confirmations and path sanitization. Overall, the task is well-scoped and proportionate to the described functionality.
Confidence: 98%
Audit Metadata