post-impl2
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's stated purpose is just to run a workflow, but it fully delegates behavior to an external Synapse CLI with auto-spawn, making the real actions opaque. No direct malicious behavior or credential theft is shown, but transitive execution and only partially verified tool provenance make the skill medium risk.
Confidence: 79%Severity: 62%
Audit Metadata