brainstorming

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core brainstorming workflow is benign and prompt-only, but the embedded recommendation to install another unpinned GitHub skill introduces unnecessary transitive supply-chain risk. No direct exfiltration or credential theft is present in this skill itself, yet the install instruction is inconsistent with a narrowly scoped ideation assistant.

Confidence: 91%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 08:38 AM
Package URL
pkg:socket/skills-sh/kevinaimonster%2Fskill-hub%2Fbrainstorming%2F@ce30bea587ae947e4935d7706e6c58f4bbd14fb0