synth-manage-checks

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in purpose and workflow, but with notable execution-trust risk because the skill requires the external gcx CLI without proving its provenance in the supplied content. Operational impact is real since it can push and delete live monitoring checks, yet the capabilities otherwise align with the stated purpose and there is no clear credential harvesting or exfiltration behavior.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Apr 7, 2026, 12:36 PM
Package URL
pkg:socket/skills-sh/grafana%2Fgcx%2Fsynth-manage-checks%2F@5be0246a801093f34140b3b36adf8a2af02fee70