lfg

Warn

Audited by Socket on Feb 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected Benign overall as an orchestration manifest for an autonomous engineering workflow. However, to reduce risk in real deployments, implement input validation for ARGUMENTS, add error handling for each step, and ensure access controls and permissions are in place for the invoked commands. The final DONE signaling should be aligned with downstream parsers to avoid misinterpretation. The code does not show credential leakage or exfiltration patterns. LLM verification: The file is a high-privilege orchestration manifest, not executable malware itself. It contains no direct evidence of obfuscated or malicious code, hard-coded secrets, or network exfiltration. However, it poses a meaningful operational security risk because it instructs automatic execution of powerful handlers without scoping, validation, or approval gates. Treat as potentially dangerous in production: restrict permissions, require human approvals, sanitize inputs, and audit handlers before enab

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 17, 2026, 04:12 PM
Package URL
pkg:socket/skills-sh/ratacat%2Fclaude-skills%2Flfg%2F@d93a59cf33da96b8bd3e3b0ff2500f1493ce5be3