todo-task-run
Warn
Audited by Socket on Feb 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The provided fragment is a coherent, purpose-aligned specification for a forward-only, sequential TODO task runner that coordinates investigations and implementations via subagents, with rigorous checkpointing and memory-tracking. No evidence of malicious activity or credential handling is detected within the fragment alone. Potential risks stem from the complexity and reliance on external Task tooling and correct TODO.md integrity; otherwise, the footprint is appropriate for its stated purpose.
Confidence: 36%Severity: 45%
Audit Metadata