ce-work
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: core git/test/PR automation matches the stated purpose, but the skill expands scope with transitive skill installation, background subagents, and mandatory third-party screenshot uploads. The biggest concern is external image hosting of potentially sensitive UI data and delegating trust to unreviewed helper skills.
Confidence: 86%Severity: 68%
Audit Metadata