homelab-setup
Warn
Audited by Socket on Apr 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose is coherent, but it asks the agent to collect many sensitive credentials in chat and store them in a shared local `.env`, while also invoking an unseen local script. There is no clear exfiltration or malicious endpoint in this excerpt, so this is not confirmed malware, but the credential concentration and incomplete trust chain create meaningful risk.
Confidence: 82%Severity: 63%
Audit Metadata