aif

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's behavior is mostly aligned with its setup purpose, but it is inherently high-risk because it installs and chains third-party skills and npm-executed MCP servers with broad agent permissions. The required local scanning/manual review is a meaningful safeguard, yet it does not remove the core transitive supply-chain and credential-forwarding risk.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
Mar 13, 2026, 10:49 AM
Package URL
pkg:socket/skills-sh/lee-to%2Fai-factory%2Faif%2F@6af48733a8460f54f615e7ed7efaa84c813897d6