LLM
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly aligned with its stated LLM-chat purpose and lacks overt malicious behavior, but trust is reduced by weak first-party provenance for the exact SDK package and by configurable baseUrl routing that could send prompts and credentials to non-official endpoints. Overall this is a moderate-risk backend integration skill rather than confirmed malware.
Confidence: 80%Severity: 52%
Audit Metadata