expedite
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow and most capabilities align with the stated expedite purpose, but the Loom integration is the main problem: it relies on a personal GitHub MCP server and forwards a live browser session cookie to third-party code. That makes install trust and credential handling disproportionate to the skill’s otherwise legitimate project-management role. Without the third-party Loom bridge, this would look mostly benign.
Confidence: 89%Severity: 84%
Audit Metadata