skill-studio
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose mostly matches its capabilities, but it relies on an external local CLI whose provenance is not independently established in the provided evidence. Voice mode’s multi-vendor credential use is plausible for the feature, yet it increases trust and data-flow risk because the CLI mediates both content and API keys.
Confidence: 81%Severity: 63%
Audit Metadata