flagrelease

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is coherent with its stated purpose as a deployment/test orchestrator, and no clear credential harvesting, covert exfiltration, or malicious deception is visible in the provided file. The main concern is medium supply-chain risk: critical behavior is delegated to unseen sub-skills that install custom packages and may use unspecified mirrors, while the skill has broad execution permissions. Overall classification: SUSPICIOUS due to incomplete provenance and broad install/exec scope, but not malicious based on the available evidence.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 25, 2026, 07:08 AM
Package URL
pkg:socket/skills-sh/flagos-ai%2Fskills%2Fflagrelease%2F@cd2b5799e754b7a0d0c9868384ac50dcefa19beb