lfg

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow is broadly aligned with autonomous engineering, but it mainly serves as an orchestrator for other skills and pushes the agent through multi-step implementation, browser testing, and PR/video actions without explicit approval gates. The main risk is transitive trust and autonomy, not confirmed malware or credential theft.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:59 AM
Package URL
pkg:socket/skills-sh/EveryInc%2Fcompound-engineering-plugin%2Flfg%2F@b66285a497731983004b11747665c4b8cf225c6d