migrate

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s migration-planning purpose broadly matches its repo analysis and refactoring behavior, but its default autonomous execution, broad write/exec capability, prompt-injection exposure from untrusted repo content, and reliance on opaque high-privilege internal sub-skills raise medium-high risk. No direct credential harvesting or explicit exfiltration is visible, so this is not confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 10, 2026, 02:19 PM
Package URL
pkg:socket/skills-sh/raddue%2Fcrucible%2Fmigrate%2F@40e3de40a9aaac5651dd99a85aeb232f61c3847b