provenance

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is legitimate and mostly aligned, but the skill expands its trust boundary by invoking third-party CLIs (`ao`, `cass`) to inspect session history, with `cass` introducing notable supply-chain risk and transcript-processing injection exposure. No direct credential harvesting or explicit exfiltration is shown, so this is not confirmed malware, but it is a medium-high risk skill footprint for its stated task.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 5, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Fprovenance%2F@7de948450b13f4147e97d4874cd13744e7cdd1bf