recipe-implement

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The visible skill is broadly consistent with an implementation orchestrator, and there is no clear credential theft or exfiltration path in the supplied text. However, its real behavior depends on an external subagents-orchestration-guide skill installed through third-party npm/marketplace paths, creating material transitive-trust and autonomy risk with limited verifiable provenance in the provided evidence.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 13, 2026, 07:10 AM
Package URL
pkg:socket/skills-sh/shinpr%2Fclaude-code-workflows%2Frecipe-implement%2F@2c18c953f651bf78bb3c90bc009528518e3e7356