checkpoint

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. Core checkpoint behavior is legitimate, but the skill is materially broader than advertised: it bundles onboarding, telemetry, proactive routing, cross-skill orchestration, and optional repo modification/commit behavior. The same-org local gstack dependency keeps this from looking malicious, but purpose-capability alignment is only partial and the hidden remote telemetry path plus repo-writing side effects make the overall skill medium risk.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 6, 2026, 03:46 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fcheckpoint%2F@c272301abcd78ddd444e1e4643b500cc3392355a