headless-ghidra-evidence
Warn
Audited by Socket on May 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent and local-only, but the skill’s core dependency is an unspecified `ghidra-agent-cli` with no verifiable install or publisher information. That makes the execution trust disproportionate to the documentation provided, though there is no clear evidence of credential theft or data exfiltration in the skill text itself.
Confidence: 86%Severity: 78%
Audit Metadata