create-task

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches its capabilities, including blockchain escrow funding, but it enables high-impact financial actions through an external CLI invoked as unpinned `@latest`. The main concerns are mutable supply-chain trust and real-world transaction capability; there is no clear evidence of credential theft or unrelated data exfiltration in the provided content.

Confidence: 86%Severity: 73%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:13 PM
Package URL
pkg:socket/skills-sh/openant-ai%2Fopenant-skills%2Fcreate-task%2F@c3186bf36e7c0c449e941032452bd711b9147f26