ce-todo-resolve

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly aligned with todo-resolution workflow, but it is not low risk: it enables autonomous code changes, git pushes, and deletion, and it transitively loads another skill not reviewed here. No clear credential theft, suspicious installer, or off-platform exfiltration appears in the provided text, so this is better classified as suspicious/high-impact workflow automation rather than malicious.

Confidence: 83%Severity: 64%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:19 AM
Package URL
pkg:socket/skills-sh/everyinc%2Fcompound-engineering-plugin%2Fce-todo-resolve%2F@3fede358668c356b74d39a084dbc0d16ba66d5a8