smart-data-analysis
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s stated routing purpose is coherent, but it depends on executing an external `kweaver`/`npx kweaver` CLI whose official provenance was not verified from the evidence. No clear credential harvesting or malicious exfiltration is shown, yet the unverifiable required CLI and broad Bash execution make the overall security risk high.
Confidence: 84%Severity: 78%
Audit Metadata