build

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent for autonomous feature development, and it does not request credentials or show direct exfiltration. However, it has meaningful security risk from broad autonomous repo access, Bash execution over repo-derived context, and especially the required transitive installation/invocation of a third-party `ship` skill.

Confidence: 81%Severity: 63%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/slamb2k%2Fmad-skills%2Fbuild%2F@095defa3ae202296b6a69cd7552376edff7e91c2