smart-data-analysis

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated routing purpose is coherent, but it depends on executing an external `kweaver`/`npx kweaver` CLI whose official provenance was not verified from the evidence. No clear credential harvesting or malicious exfiltration is shown, yet the unverifiable required CLI and broad Bash execution make the overall security risk high.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:19 AM
Package URL
pkg:socket/skills-sh/kweaver-ai%2Fkweaver-dip%2Fsmart-data-analysis%2F@bd210b702c3d112ec6401d72b6db33eb9e99f48f