lab-retro

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Most capabilities match a retrospective skill, but the final feedback step routes participant data through an unverifiable Vercel proxy rather than the official Baserow API. This is a data-flow integrity issue and makes the skill higher risk than its stated purpose warrants, though there is no clear evidence of credential theft or confirmed malware.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Apr 10, 2026, 09:50 PM
Package URL
pkg:socket/skills-sh/glebis%2Fclaude-skills%2Flab-retro%2F@80d64de33ffc8847f57acf045819664358574850