clipping
Warn
Audited by Socket on Apr 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is plausible, but the skill's main action relies on an unverifiable external CLI with no documented provenance. Because remote content and local vault context are funneled into that black-box tool, the install-trust and data-flow risks are disproportionate to the minimal documentation provided.
Confidence: 87%Severity: 84%
Audit Metadata