dev-task-queue

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s behavior is mostly aligned with its stated purpose, but its core trust model is weak: it asks the agent to clone and execute task-management scripts from an unverifiable personal GitHub repo, then push task data to that remote. This is better classified as suspicious supply-chain and data exposure risk than confirmed malware.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:38 AM
Package URL
pkg:socket/skills-sh/molechowski%2Fclaude-skills%2Fdev-task-queue%2F@62a7366b3425cd97e143d28432b4a93d28594d27