godot-interactive

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability is coherent for Godot testing, and data flows stay local, but install trust is weakened by the placeholder repo/publisher mismatch and reliance on a community MCP server. This looks like a legitimate testing skill with moderate supply-chain risk rather than credential theft or overt malware.

Confidence: 91%Severity: 56%
Audit Metadata
Analyzed At
Mar 30, 2026, 11:13 AM
Package URL
pkg:socket/skills-sh/bfollington%2Fterma%2Fgodot-interactive%2F@7bc139d1fdb598b865cb88e552bdbd1943871a22