LLM

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with its stated LLM-chat purpose and lacks overt malicious behavior, but trust is reduced by weak first-party provenance for the exact SDK package and by configurable baseUrl routing that could send prompts and credentials to non-official endpoints. Overall this is a moderate-risk backend integration skill rather than confirmed malware.

Confidence: 80%Severity: 52%
Audit Metadata
Analyzed At
Mar 16, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/jjyaoao%2FHelloAgents%2Fllm%2F@6795a1900f165f7f2a3b73af0db518aa9e9588fc