draft-review
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose is coherent and the skill is mostly a benign document-review workflow, but it introduces medium-risk trust issues through optional third-party OCR tooling, transitive role installation, and delegated processing of untrusted document content. No clear credential theft, exfiltration endpoint, or malicious mismatch is present in the supplied skill text.
Confidence: 87%Severity: 56%
Audit Metadata