compound-engineering-lfg

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is a thin autonomous orchestrator that chains several external skills, including an optional unrelated one, and instructs the agent to complete all steps without pausing. Its main risk is transitive trust and autonomous action, not direct malware behavior or credential theft in the shown text.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/udecode%2Fbetter-convex%2Fcompound-engineering-lfg%2F@a3e1a62eb52b7a3787ce44425c901cf43f98a3a3