slfg

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the wrapper’s purpose matches an engineering orchestration skill, but its autonomy is disproportionate because it mandates uninterrupted multi-agent execution through code changes, testing, and PR updates. Install provenance for the referenced main plugin looks reasonably consistent, so the primary risk is autonomous action and delegated trust to downstream skills rather than confirmed malware or credential theft.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Mar 27, 2026, 05:27 PM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Fslfg%2F@40d601e077211a7c82895e9b4316aa61d537b38d