french-tutor

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core French-tutor behavior is coherent and mostly benign, but the optional Mochi integration is not. It routes card content and likely a Mochi API key through an unverified cross-skill local script rather than Mochi's official documented API flow. That disproportionate third-party credential forwarding and transitive trust materially raise risk even though there is no clear evidence of outright malware.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Apr 11, 2026, 02:07 PM
Package URL
pkg:socket/skills-sh/hartreeworks%2Fskill--french-tutor%2Ffrench-tutor%2F@a3e8dd556f08ea45c2de0ed74b1749fd9b2f8a3b