vibekanban

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and uses a consistent official install path, so it does not look malicious. However, it is a high-risk orchestration skill because it grants autonomous coding agents broad shell and git authority by default, can expose copied secrets like `.env`, and accepts untrusted project/task content while retaining execution capability.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 20, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/itechmeat%2Fllm-code%2Fvibekanban%2F@db6a21cea483b28d047cb10a9e3093ddab0655aa