facts-discover

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent and mostly local, with no credential harvesting or external data exfiltration. However, its core workflow relies on an undocumented `facts` CLI whose provenance cannot be verified from the skill, creating a significant supply-chain trust gap. The overall footprint fits the stated purpose, but the missing trust chain for the required executable makes the skill medium-high risk rather than benign.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 3, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/av%2Ffacts%2Ffacts-discover%2F@3b353477e7dc84935eba6178b959858dc7772462