prd-progress

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The prd-progress skill appears benign and coherently aligned with its stated purpose: it reads local PRD and task markdown files, derives progress metrics, and outputs results in multiple formats without invoking external services, collecting secrets, or performing privileged actions. The data flows are contained to local files and stdout, which is appropriate for a project-management utility. No evident insecure or risky patterns (downloading binaries, credential handling, or external network communication) are present in the described workflow. Overall, the footprint is proportional to the asserted functionality and maintains reasonable security posture.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/jpoutrin%2Fproduct-forge%2Fprd-progress%2F@06f23bcbdfd098af669b866b6a067fa3d04a9cee