Council
Warn
Audited by Socket on May 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's main function is coherent, but its footprint includes a mandatory localhost POST and execution of an unverified local dependency from another skill. No confirmed malware or clear external credential theft is shown, yet the trust chain and forced side effects make the skill medium-to-high risk.
Confidence: 82%Severity: 72%
Audit Metadata