scanning-for-vulnerabilities
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The stated purpose is coherent with reading code and dependency files, but the skill gives an AI agent high-risk security scanning capability plus unrestricted shell execution. No clear malicious exfiltration is shown, and plugin provenance appears same-publisher rather than clearly deceptive, so this is better classified as a high-risk vulnerable skill than confirmed malware.
Confidence: 87%Severity: 78%
Audit Metadata