tech-blog

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

该技能主体是普通技术写作指导,未请求凭据、未读取敏感文件、未进行网络中转,整体功能与声明基本一致。但它包含一次与主功能无关的转安装建议,且指向未验证的第三方技能仓库路径,带来明显的转移信任与供应链风险。因此应判定为 SUSPICIOUS,而非恶意。

Confidence: 91%Severity: 58%
Audit Metadata
Analyzed At
Apr 1, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/kevinaimonster%2Fskill-hub%2Ftech-blog%2F@7dffb16b1ead04e9a5c317298128318ccc036745