start-issue
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s footprint is coherent with its stated purpose: a local automation to manage Marshroom issues, update running status, and prepare a development branch. The use of local state updates, repository checks, and optional marsh CLI usage are proportionate and expected for such a task. No credentials or external data flows are introduced, and the actions are constrained to the developer’s environment. Overall risk is Low to Moderate due to shell command execution and file writes, but nothing indicates malicious intent or malfeasance in this isolated fragment.
Confidence: 75%Severity: 75%
Audit Metadata