privacy-parser-pii-extraction

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core functionality matches the stated purpose, and there is no clear credential theft or exfiltration path, but install trust is weak: the publisher/source relationship is inconsistent, the code is installed from a personal GitHub repo, and the large model checkpoint download is undocumented and unverifiable. Main concern is supply-chain risk, not confirmed malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 27, 2026, 01:44 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fprivacy-parser-pii-extraction%2F@1922f4dfbc5c6e44c350c17102d10f1b08926dc1