bobo-skill

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is narrow and mostly aligned with the described behavior, and there is no clear credential theft or exfiltration. However, trust is weakened by reliance on an unseen local generator and a non-pinned image from a personal-looking Quay namespace, making this higher risk than a purely static manifest template.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:32 AM
Package URL
pkg:socket/skills-sh/cooloo9871%2Fmy-awesome-skill%2Fbobo-skill%2F@aa160ff6c276ae691be84a70c64ff4df7af5204f