incident-report

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core incident-reporting functionality is benign and well-scoped, with no credential or data-exfiltration behavior. However, the embedded recommendation to install another skill introduces a transitive trust risk, and the specific target `github:mindverse/skillhub` was not verifiable from the available evidence. Overall risk is driven by that install recommendation, not by the reporting workflow itself.

Confidence: 91%Severity: 52%
Audit Metadata
Analyzed At
Apr 1, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/kevinaimonster%2Fskill-hub%2Fincident-report%2F@f62e3551fb8c73fab0310bdad3e65fbfcfd7318b