explain-code
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is benign, but the skill expands scope by requiring a separate skill, fetching broad untrusted web content, and using ambiguous/unpinned Playwright CLI execution. No direct credential harvesting or malicious exfiltration is present, but supply-chain and prompt-injection exposure are material.
Confidence: 87%Severity: 58%
Audit Metadata