sync

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS due to install/execution trust, not because the workflow is misaligned. The skill’s git/Linear/project-reading capabilities match its purpose, and its data flows are mostly direct and proportionate. The main concern is reliance on a non-official third-party `linear` CLI for authenticated Linear operations, which creates a medium supply-chain and credential-forwarding risk even though the tool appears open-source and verifiable.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 4, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/seangjr%2Fproduct-skills%2Fsync%2F@8183f81e7faf840534f6b9ab8dd4ae215d1724de