french-tutor
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The core French-tutor behavior is coherent and mostly benign, but the optional Mochi integration is not. It routes card content and likely a Mochi API key through an unverified cross-skill local script rather than Mochi's official documented API flow. That disproportionate third-party credential forwarding and transitive trust materially raise risk even though there is no clear evidence of outright malware.
Confidence: 89%Severity: 82%
Audit Metadata