adapt-materal-enums
Audited by Socket on Feb 27, 2026
1 alert found:
AnomalyThis SKILL.md is a workflow for adapting enums using a third-party CLI (aptx-ft) and human/LLM translation steps. It does not contain executable code, obfuscated payloads, or direct mechanisms for credential harvesting or network exfiltration. The primary supply-chain risks are: (1) installing/running an unpinned third-party CLI from a package registry without checksums, and (2) trusting an arbitrary provider base-url that could return manipulated data. The workflow's requirement to delete intermediate files is reasonable for hygiene but reduces forensic trace if misuse occurs. Overall the document is coherent with its stated purpose and presents low technical maliciousness, but operators should pin/verify the aptx-ft package and ensure the provider API is trusted.