popsicle

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated documentation-audit purpose, but it carries meaningful risk from transitive skill installation, autonomous repeated git commits, and agent subprocess execution. No clear credential theft or covert exfiltration is present in the core workflow, so this is better classified as suspicious/high-risk automation than malicious.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
May 2, 2026, 05:45 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fpopsicle%2F@e8f65fa655a349899c4c96f28b1de55a431eb741