iii-core-primitives
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Mostly coherent documentation for iii primitives, but it expands execution trust by instructing installation of registry, OCI, and local workers that may run arbitrary code or add powerful capabilities. No direct credential harvesting or confirmed exfiltration is shown, so this is better classified as medium-risk/suspicious supply-chain and transitive-trust exposure rather than malware.
Confidence: 87%Severity: 58%
Audit Metadata