bugfix

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is mostly coherent with a bug-fixing purpose, but its trust surface is larger than the description suggests: broad local execution rights, reliance on an external hoyeon-cli with no provenance here, and delegation to other skills for implementation/QA. No clear credential theft or exfiltration is shown, so this is better classified as suspicious/high-risk workflow design rather than malicious.

Confidence: 72%Severity: 72%
Audit Metadata
Analyzed At
Apr 8, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fhoyeon%2Fbugfix%2F@48abbe5dfc416debe2be5586d59e7700628d6b8b