aeo

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and requested capabilities are mostly aligned, but it relies entirely on an unpinned third-party npm CLI invoked via npx @latest and forwards multiple API keys into that package. This looks more like a supply-chain and credential-handling risk than confirmed malicious behavior.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
Mar 27, 2026, 03:10 AM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Faeo%2F@c694a9fad3ad1594352ea0e6bbb7bd88125905cb