implement
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core behavior is mostly aligned with a full-power implementation workflow, but its footprint is large: broad execution/edit permissions, automatic local hooks, external MCP dependencies, and transitive skill/agent trust. The main concern is not clear malware behavior, but medium security risk from ambiguous memory-server provenance, external data routing, and highly autonomous repo modification capabilities.
Confidence: 80%Severity: 57%
Audit Metadata