task-loop-verify

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's described capabilities are coherent with its stated purpose: it reads loop state, fetches the corresponding task prompt, delegates verification to a dedicated verifier, and emits a completion marker based on the outcome. Data access is confined to local configuration/state files and internal tooling; there are no explicit credential or external network flows described. The design is proportionate to a tooling/automation helper for task loops. Minor risks exist around internal agent dependencies and prompt content validation, but there is no evident credential exposure or supply-chain behavior. Overall verdict: BENIGN with LOW to MEDIUM security concerns arising from reliance on internal agents and prompt content validation; no malicious indicators detected.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:52 AM
Package URL
pkg:socket/skills-sh/jsegov%2Fshipspec-claude-code-plugin%2Ftask-loop-verify%2F@e4b038063028b351552922ca7aae0ef0e314c545