facts-refine

Warn

Audited by Socket on May 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and actions are coherent and local-only, with no visible credential or exfiltration behavior, but it depends on an unverifiable `facts` CLI whose provenance is not documented. That supply-chain uncertainty is disproportionate enough to keep overall risk high despite otherwise benign behavior.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 3, 2026, 05:39 PM
Package URL
pkg:socket/skills-sh/av%2Ffacts%2Ffacts-refine%2F@efa14081ed708736c1cabbc4e852baf7d01145f0