pdca
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the visible PDCA workflow is coherent and mostly local, but trust in the underlying bkit MCP toolchain is not established, and the skill combines repository-content ingestion with autonomous write capability during iterate. No clear credential harvesting or exfiltration is present, so this is not confirmed malware.
Confidence: 82%Severity: 56%
Audit Metadata