dune-app-review

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious. The stated purpose matches a Dune app review, and the GitHub source is plausibly official, but the skill delegates its real behavior to mutable remote markdown fetched at runtime and then executed as instructions with Shell/Write permissions. This creates medium-high security risk from remote instruction injection and unpinned trust, even without clear malicious intent.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Apr 16, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/cognitedata%2Fdune-skills%2Fdune-app-review%2F@46f5b6097497da52a41edfa10155f4ed2448d2a8