build-implementation
Warn
Audited by Socket on Mar 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose matches using a planning CLI, but it over-trusts external CLI output and instructs the agent to execute that output autonomously. The main risk is not obvious credential theft; it is supply-chain trust plus indirect prompt injection from CLI-generated content into code-changing actions.
Confidence: 84%Severity: 74%
Audit Metadata