sdd-update

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose mostly matches its capabilities for clerical spec maintenance, but it depends on an opaque `sdd` CLI and can execute verification commands from spec metadata, plus perform repo-changing git actions. The footprint is not overtly malicious and shows no clear credential harvesting or exfiltration, but the unverifiable CLI dependency and command execution authority make it medium risk.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
May 7, 2026, 10:17 AM
Package URL
pkg:socket/skills-sh/tylerburleigh%2Fclaude-sdd-toolkit%2Fsdd-update%2F@c7b574f14cde3218832484e201ee9a134382dbe3