vibekanban
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-aligned and uses a consistent official install path, so it does not look malicious. However, it is a high-risk orchestration skill because it grants autonomous coding agents broad shell and git authority by default, can expose copied secrets like `.env`, and accepts untrusted project/task content while retaining execution capability.
Confidence: 88%Severity: 74%
Audit Metadata