work-milestone
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its purpose, but its footprint is high-risk for an AI skill because it spawns multiple full-power orchestrators, processes external task content, and can autonomously merge and push to main. This looks more like dangerous over-broad automation than credential theft or confirmed malware.
Confidence: 91%Severity: 78%
Audit Metadata