complete-implementation
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's core workflow is coherent for implementation verification, and there is no clear credential theft or malicious exfiltration. Risk comes from high-authority automation: automatic hook execution, transitive skill invocation, recursive task execution, and autonomous commit/push/backlog mutations. This looks like a powerful orchestration skill with medium-high operational risk rather than confirmed malware.
Confidence: 84%Severity: 67%
Audit Metadata