post-impl2

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is just to run a workflow, but it fully delegates behavior to an external Synapse CLI with auto-spawn, making the real actions opaque. No direct malicious behavior or credential theft is shown, but transitive execution and only partially verified tool provenance make the skill medium risk.

Confidence: 79%Severity: 62%
Audit Metadata
Analyzed At
Mar 28, 2026, 04:41 AM
Package URL
pkg:socket/skills-sh/s-hiraoku%2Fsynapse-a2a%2Fpost-impl2%2F@823396ffb40be7ab3e74eb8607cfa9e41faafacc