bf-lead-implement

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment presents a coherent Lead-driven orchestration pattern for epic-level TDD implementation, with a clear single-write policy to sprint-status.yaml and well-defined pathways for normal and stuck scenarios. The approach emphasizes governance, reproducibility, and auditability, while introducing operational risk around rigidity and tool/version dependencies. The overall security posture is benign, with moderate operational risk tied to process rigidity and access controls around the central write point. Recommended mitigations include strong IAM controls on repository write access, explicit validation of conventions and library references before inline propagation, and fallback procedures that ensure continuity if the Lead’s single write point encounters issues.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/khaki4%2Fmy_skills%2Fbf-lead-implement%2F@349d57e6d832fe0a4aa2f0a229b8801337e523e8