start

Warn

Audited by Socket on Feb 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] No explicit malware or credential harvesting patterns are present in this skill instruction. The capabilities align with the described purpose. The main security risk is execution of repository-controlled scripts (done-cleanup.sh, start-worktree.sh) discovered and invoked by the skill: if an attacker can place or modify files under .claude/skills, they could run arbitrary commands locally, modify repo state, or exfiltrate data. There are no remote download-and-execute patterns, no hardcoded secrets, and external calls appear to be to the expected Linear MCP tools. Recommendation: treat these scripts as sensitive — verify .claude/skills contents before running, avoid running in untrusted repositories, and ensure MCP credentials are stored securely. LLM verification: Functionally the skill is coherent with its stated purpose: creating a Linear issue, creating a git worktree, recording session state, and opening a local Claude session. It does not contain obvious malicious code in the fragment shown. However, it executes repository-provided shell scripts and spawns local processes (osascript -> Terminal -> claude). Those execution sinks are high-impact: if an attacker can modify files in .claude/skills or supply a malicious repository, they can execute arbitr

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 24, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/team-plask%2Fsession-workflow%2Fstart%2F@39994812d971fbf6f967e573344bb04534448445