humanize

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is operationally consistent (parses input, uses an API key, calls a remote endpoint, returns results) but is suspicious because its explicit purpose is to help users bypass AI/plagiarism detectors. The primary risks are privacy/data-exfiltration (user text sent to a third party with unknown retention/training policies) and enabling unethical misuse (academic dishonesty, evasion of detection). There is no sign of traditional malware, obfuscation, or system-level backdoors, but the skill should be treated as suspicious and its use restricted/monitored. Recommend adding explicit warnings about acceptable use, privacy/retention details, and an option for local-only processing; consider rejecting or tightly gating 'bypass' functionality.

Confidence: 80%Severity: 70%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:54 PM
Package URL
pkg:socket/skills-sh/humanizerai%2Fagent-skills%2Fhumanize%2F@6f6fc915df2cd736af291f729410b08dcd9d9799