phase-contract-workflow

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is mostly aligned with its stated workflow-scaffolding purpose and does not show malware, credential harvesting, or suspicious third-party installation behavior. The main security concern is autonomy: it empowers the agent to make repo-wide changes and automatically commit/push them, which is a high-impact action even though it is framed as milestone management. Overall this is not malicious, but it is a high-risk automation skill that should only run with strong user oversight on trusted repositories.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
May 1, 2026, 12:02 PM
Package URL
pkg:socket/skills-sh/nanzhipro%2Fphase-contract-workflow-skill%2Fphase-contract-workflow%2F@b76f3efcbcd5ba08dd7b199d2e2178290cf68583