agkan-add

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow itself is coherent for backlog task creation and does not request excess credentials or exfiltrate data, but it relies on an unverifiable external agkan binary with unclear provenance. That supply-chain gap is the main risk; absent stronger evidence of official ownership or signed releases, this should not be treated as fully benign.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Apr 8, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/gendosu%2Fagkan-skills%2Fagkan-add%2F@1980a63e0a9d4c8d8bd09a30b1b587b99fd28c93