caveman-discover
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's behavior is mostly coherent with its stated purpose: it inventories LLM workflows, proposes labels, edits only after approval, and applies minimal code changes. The main risk is not hidden malware but third-party gateway mediation: the workflow labeling model depends on Caveman-routed API traffic, and broader Caveman docs indicate provider-related headers/keys may be forwarded through Caveman infrastructure. That proxying is proportionate to the product but creates medium security risk and weaker data-flow integrity than direct provider calls.
Confidence: 87%Severity: 56%
Audit Metadata