gastown
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The fragment presents a coherent, feature-rich Gas Town orchestration model with strong autonomy potential. While powerful and justifiable for advanced users, it introduces meaningful supply-chain and execution risks due to autonomous CLI invocations, external downloads, and network access. Risks are mitigable with strict provenance controls, per-action user approvals, least-privilege execution, and robust auditing. Treat as SUSPICIOUS with emphasis on provenance pinning, hash verification, and sandboxed execution; enforce explicit confirmations for non-local operations, and implement mandatory monitoring/auditing for all external downloads and CLI invocations.
Confidence: 65%Severity: 58%
Audit Metadata