architect
Audited by Socket on Feb 23, 2026
1 alert found:
Security[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] The analyzed skill fragment is benign in intent and scope, with coherent data flows and trustworthy external tooling usage. It warrants standard credential hygiene (least privilege, scoped tokens, auditing) but does not exhibit malicious behavior or supply-chain exploitation patterns. LLM verification: The skill fragment coherently describes an architecture/design orchestration workflow, including phases, outputs, and automation hooks. It does not contain executable payloads or credential handling in the artifact itself. Primary risk stems from embedded command-like templates and reliance on external automation tools; ensure strict input validation, least-privilege access, and sandboxed execution when integrating into automation pipelines. Overall risk is low-to-moderate with attention to exec