gastown
Warn
Audited by Socket on Mar 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s broad orchestration behavior generally matches its stated purpose, but it has a large execution footprint: unrestricted shell access, multi-agent code modification/merge capability, and incomplete install provenance for the gt/bd CLIs. No clear credential theft or exfiltration is shown, so this is not confirmed malware, but it carries meaningful operational and supply-chain risk.
Confidence: 75%Severity: 67%
Audit Metadata