build
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's development-orchestration purpose broadly matches its local read/write and testing capabilities, but it has elevated risk because it installs and depends on another external skill (`ship`) and then grants substantial autonomous execution across subagents. No direct credential theft or exfiltration is evident, but the transitive skill install and high-autonomy workflow make it a medium-high security risk.
Confidence: 86%Severity: 72%
Audit Metadata