electron
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is largely aligned with its stated purpose and uses plausible local CDP automation patterns, but it is still high-impact. Main concerns are unpinned `npx` execution and the ability to control communication/productivity apps with real-world consequences; there is no clear evidence of covert exfiltration or a malicious third-party gateway.
Confidence: 86%Severity: 58%
Audit Metadata