coding-tutor
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's teaching and file-writing behavior is broadly consistent with its educational purpose, but it relies on a same-publisher download-and-execute chain for helper scripts that are not pinned, signed, or independently inspectable from the provided evidence. Main risk is supply-chain trust rather than clear malicious behavior or credential theft.
Confidence: 81%Severity: 56%
Audit Metadata