ship
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly fit its stated PR-shipping purpose and installer trust is reasonable, but it grants an agent broad autonomous repository actions including push, PR creation, CI-driven edits, and merge. Risk is driven by action scope and transitive/local subagent trust, not clear credential theft or malicious exfiltration.
Confidence: 85%Severity: 68%
Audit Metadata