harvest
Warn
Audited by Socket on Apr 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose and local file operations are broadly coherent for knowledge consolidation, and the skill text shows no explicit credential capture or external data routing. However, it relies on an unverifiable `ao` CLI with no confirmed official install or release provenance in the provided evidence, which creates a significant supply-chain trust gap.
Confidence: 83%Severity: 72%
Audit Metadata