brief

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose matches its broad read-only legal briefing scope, so there is no strong purpose-capability mismatch. The main concerns are install trust and incomplete data-flow transparency: external evidence points to third-party npx/community-hub distribution, and the connector implementation is not shown, so credential routing and API endpoints cannot be verified. This is not confirmed malware, but it carries meaningful supply-chain and sensitive-data handling risk.

Confidence: 78%Severity: 56%
Audit Metadata
Analyzed At
Mar 13, 2026, 11:59 PM
Package URL
pkg:socket/skills-sh/anthropics%2Fknowledge-work-plugins%2Fbrief%2F@0b893239a2c0b5b46cf2dc01f709a9aff21daca1