start
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s onboarding purpose mostly matches its file reads and recommendations, but it includes execution of an unverifiable local CLI script with no documented provenance or trust chain. No clear credential theft or exfiltration is shown, so this is not confirmed malware, but the opaque local executable pushes overall risk into medium-high territory.
Confidence: 83%Severity: 72%
Audit Metadata