booth-deck
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow is mostly aligned with a coding worker skill, but it relies on an unverifiable `booth` CLI as its control/reporting channel and grants the agent autonomous commit/reload behavior. I see no confirmed credential theft or overtly malicious behavior, but the opaque CLI and operational autonomy make the skill high risk.
Confidence: 82%Severity: 78%
Audit Metadata