cruise-control

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The cruise-control capability represents a coherent, auditable automation orchestrator for a multi-gear StackShift workflow. It is not inherently malicious and fits its stated unattended-run use. Primary concerns are operational risk (unreviewed, large-scale changes) and governance (access control, artifact handling, and secure integration points). With proper safeguards—access controls, input validation, robust state management, and clear rollback paths—the feature remains a valuable automation tool rather than a security threat.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 1, 2026, 08:15 AM
Package URL
pkg:socket/skills-sh/jschulte%2Fclaude-plugins%2Fcruise-control%2F@8ac58f128c50c4c9937a601281d21f147f9155b6