ashby
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The task scope fits recruiting operations, but the core dependency is an unverified `ashby` CLI that receives Ashby API credentials and candidate data without documented same-org provenance in the provided evidence. That makes the skill high risk even though its stated purpose is coherent.
Confidence: 86%Severity: 82%
Audit Metadata