completo-briefing
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's local file access is broadly consistent with creating a project briefing, but its trust boundary is weak: it relies on an unverifiable `completo` CLI and sends synthesized internal project context to an undisclosed remote service. The purpose is plausible, yet the undocumented binary provenance and opaque network destination make the overall risk high.
Confidence: 86%Severity: 82%
Audit Metadata