arize-evaluator

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely purpose-aligned with Arize evaluator management and uses same-org Arize concepts/endpoints, but it asks the agent to read local `.env` secrets and forward multiple credentials into the `ax` CLI while the CLI’s installation/provenance is not established in the provided material. This looks more like a legitimate but medium-risk operational skill than malware; the main concerns are credential handling and unverifiable execution trust for the required CLI.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
Apr 2, 2026, 01:05 AM
Package URL
pkg:socket/skills-sh/github%2Fawesome-copilot%2Farize-evaluator%2F@e17adf992ae78598a29d3343984808397adfa817