neovim
Fail
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill's footprint is coherent with its stated purpose: it enables legitimate, local automation of a Neovim instance via RPC to inspect state and execute code. The data access is appropriate for editor automation and does not introduce external data flows or credential harvesting. Overall risk is low to moderate (Benign) given proper user context and explicit permission to control the local editor. Monitor for accidental exposure of sensitive editor data when querying buffers or LSP state, but nothing indicates malintent or external data exfiltration.
Confidence: 98%
Audit Metadata