lfg

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose matches an engineering workflow, but the skill is a thin orchestration layer that delegates to multiple external commands, creating a transitive-trust problem and enabling broad autonomous code-changing behavior with limited per-step user approval. No direct credential theft, exfiltration endpoint, or malicious payload appears in this fragment, but the chained execution model and immediate-action instruction make it medium risk.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/udecode%2Fbetter-convex%2Flfg%2F@cdd86c092b0b659859e61fdf56d42c9a05f615ac