Falco Runtime Security
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core functionality is broadly consistent with Kubernetes/Falco runtime inspection, but the install path introduces medium trust risk because it requires a third-party `npx skills add` CLI from an unrelated org and creates a transitive skill trust chain. No clear malicious data exfiltration or credential-harvesting behavior is shown from the provided content.
Confidence: 80%Severity: 56%
Audit Metadata