lfg

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is mainly an orchestrator for other skills, but it hides most real behavior behind unverified slash-command dependencies and pushes a highly autonomous workflow through coding, review, browser testing, and PR/video steps. No direct malware or credential-harvesting logic is visible in this file, yet the transitive trust chain and broad autonomous action surface make the overall risk high.

Confidence: 80%Severity: 76%
Audit Metadata
Analyzed At
Mar 27, 2026, 05:27 PM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Flfg%2F@71aff41343f9a12c55062d154f14dbb903ecaf4c