risk-management-specialist

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the available evidence shows a legitimate-looking but trust-expanding install flow that fetches a separate CLI and then installs a third-party skill from GitHub. With no visibility into the skill's actual SKILL.md contents, permissions, credential requirements, or outbound endpoints, the main concern is transitive trust and runtime installer risk rather than confirmed malicious behavior.

Confidence: 78%Severity: 64%
Audit Metadata
Analyzed At
Apr 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Frisk-management-specialist%2F@c80dd38c28259fe7959273c6b2c5176e24252794