pipeline

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's core behavior is largely aligned with its stated purpose as a build-pipeline orchestrator, so this is not confirmed malware. The main concerns are its explicit transitive installation of other skills via an unpinned `npx` path and its ability to autonomously push and auto-merge code, which create meaningful supply-chain and autonomy risk beyond a low-risk documentation skill.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:56 PM
Package URL
pkg:socket/skills-sh/jwilger%2Fagent-skills%2Fpipeline%2F@6412838f627bb3c787c7a65ec9ded324efef27e1