ai-dev-loop
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but it gives AI agents broad autonomous development authority and lets untrusted task/PRD content influence code-writing and command-capable workflows. There is no clear credential theft or exfiltration, yet the autonomy plus prompt-injection exposure makes this a medium-risk orchestration skill rather than benign documentation.
Confidence: 82%Severity: 58%
Audit Metadata