kata-execute-phase

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior mostly matches its stated purpose as a phase executor, and it does not show obvious credential theft or off-platform exfiltration. However, it grants broad autonomous repository and GitHub control, uses transitive skill loading, trusts many unseen local scripts, and passes large amounts of project content into write-capable subagents, creating meaningful medium-high security risk without clear evidence of confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 10, 2026, 12:01 PM
Package URL
pkg:socket/skills-sh/gannonh%2Fkata-orchestrator%2Fkata-execute-phase%2F@4cabce7589e0d2d62a9a29dd8aa37b6b3d9a78ad