major-task

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent for a repo-planning skill, but it expands trust through explicit helper-skill loading, unpinned cloning, and autonomous tracker/PR actions. Main risk is transitive skill installation plus processing untrusted external content while retaining write/exec capability, not overt malware or credential theft.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Apr 4, 2026, 01:32 AM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Fmajor-task%2F@8c8384c9d5eee2b1c816bf268b2b3dc242e966cc