task

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose and does not show clear malware or suspicious installer behavior, but it is high-impact orchestration: it reads untrusted tracker content, can edit/execute locally, loads additional skills, and by default performs public/external actions like PR creation and issue comments. Main risk is autonomy plus indirect prompt injection, not credential theft or covert exfiltration.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Apr 4, 2026, 01:32 AM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Ftask%2F@a7d65de797db54a48150be2b3193a91365d339b3