task-writer
Warn
Audited by Socket on Mar 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The analyzed fragment is a benign, developer-facing specification for constructing Mechanic tasks. There are no evident malicious data flows, credential handling, or remote execution patterns within the supplied code. The payload consists of templates, example Liquid blocks, and JSON formats meant for task generation; network or credential exposure risks would arise only if a user misconfigures the downstream task JSON or executes the examples with real data. Overall, the footprint is coherent with its stated purpose and proportionate to a documentation/template role.
Confidence: 75%Severity: 75%
Audit Metadata