quality

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall SUSPICIOUS rather than malicious. The skill’s capabilities mostly match a CI-style quality review, but its trust model is weakened by reliance on an unverifiable noodle CLI that receives a session identifier. No clear exfiltration or deceptive behavior is shown, yet the unverifiable binary and autonomous workflow control make this a high security-risk skill.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Mar 22, 2026, 01:17 AM
Package URL
pkg:socket/skills-sh/poteto%2Fnoodle%2Fquality%2F@432892b2599662153e994cca50b233891d73706e