ai-native-dev

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document describes a plausible and useful automation for updating TASKS.md, but its explicit instruction to operate autonomously without asking permission and the lack of runtime, credential, and safety controls present a non-trivial supply-chain and repository-integrity risk. There are no direct code-level signs of malware in this text, but the unspecified runtime/credential model and unrestricted write behavior could be abused or accidentally cause damage. Recommend: require an opt-in authorization model, least-privilege scoped credentials, explicit documentation of runtime/execution environment, audit logging, allowlist of repositories/branches, sanitization of untrusted inputs, and a human-in-the-loop approval for pushes in sensitive repositories before using this skill.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 09:41 AM
Package URL
pkg:socket/skills-sh/junhua%2Fforth-ai-homepage%2Fai-native-dev%2F@f9c766fa86ce3e96782f9e927d042d67b4a76fcd