checkpoint
Warn
Audited by Socket on Apr 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. Core checkpoint behavior is legitimate, but the skill is materially broader than advertised: it bundles onboarding, telemetry, proactive routing, cross-skill orchestration, and optional repo modification/commit behavior. The same-org local gstack dependency keeps this from looking malicious, but purpose-capability alignment is only partial and the hidden remote telemetry path plus repo-writing side effects make the overall skill medium risk.
Confidence: 86%Severity: 58%
Audit Metadata