beads

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core bd usage guidance is broadly aligned with issue tracking, but the skill normalizes a raw GitHub curl|bash installer from a personal repo and explicitly promotes stealth mode and permission-avoidance behavior. No direct credential theft or off-platform data exfiltration is shown, so this is not confirmed malware, but the install path and concealment cues make the skill higher-risk than a typical CLI helper.

Confidence: 86%Severity: 69%
Audit Metadata
Analyzed At
Mar 14, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/schlenks%2Fsuperpowers-bd%2Fbeads%2F@371112e2756cbc6280611fe7ab8f6a00ed9c8b40