juicebox-cost-tuning
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is benign, but the visible skill is underspecified and grants broader shell/network capabilities than its cost-optimization role requires. No explicit malicious or credential-stealing behavior is shown, yet the wildcard `curl`/`gh` permissions and third-party authorship make the skill riskier than a normal documentation-style guide.
Confidence: 81%Severity: 61%
Audit Metadata