completo-briefing

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's local file access is broadly consistent with creating a project briefing, but its trust boundary is weak: it relies on an unverifiable `completo` CLI and sends synthesized internal project context to an undisclosed remote service. The purpose is plausible, yet the undocumented binary provenance and opaque network destination make the overall risk high.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Mar 29, 2026, 09:24 PM
Package URL
pkg:socket/skills-sh/scalecommerce-dev%2Fcompleto%2Fcompleto-briefing%2F@3369212ed45f511c3b69828162f734bba971b887