execute

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s implementation workflow is mostly purpose-aligned for software delivery, but it grants unusually broad autonomous authority: no user confirmation, continuous execution, sub-agent spawning with bypassPermissions, and external backend signaling. Its dependence on the `noodle` CLI from a personal-domain distribution path with limited release verification further raises supply-chain risk. I do not see clear credential harvesting or confirmed malware, but the autonomy and install-trust profile make this a high-risk execution skill.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Mar 22, 2026, 01:17 AM
Package URL
pkg:socket/skills-sh/poteto%2Fnoodle%2Fexecute%2F@006f7c5fc3c2eec6a8679c0b20003778a8499e8b