sync
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS due to install/execution trust, not because the workflow is misaligned. The skill’s git/Linear/project-reading capabilities match its purpose, and its data flows are mostly direct and proportionate. The main concern is reliance on a non-official third-party `linear` CLI for authenticated Linear operations, which creates a medium supply-chain and credential-forwarding risk even though the tool appears open-source and verifiable.
Confidence: 82%Severity: 58%
Audit Metadata