auto-dev

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior broadly matches its stated autonomous-dev purpose, but its footprint is high-trust and high-impact. Official tool provenance lowers supply-chain concern, yet unpinned MCP execution, broad 'any skills/MCP tools' authority, live credential handling, web-content ingestion with write/exec ability, and deploy/push capabilities make this a medium-risk autonomous skill rather than a benign low-risk helper.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:40 AM
Package URL
pkg:socket/skills-sh/xiaojiongqian%2Fskills-hub%2Fauto-dev%2F@a9b7a4953198233f597c1b926d3e32861e6f4159