dune-app-review
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Suspicious. The stated purpose matches a Dune app review, and the GitHub source is plausibly official, but the skill delegates its real behavior to mutable remote markdown fetched at runtime and then executed as instructions with Shell/Write permissions. This creates medium-high security risk from remote instruction injection and unpinned trust, even without clear malicious intent.
Confidence: 89%Severity: 72%
Audit Metadata