basedagents
Warn
Audited by Socket on Apr 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is broadly aligned with its stated registry/messaging purpose and uses plausible first-party endpoints, so it is not strongly indicative of malware. The main risks are unpinned npm execution via npx and the ability to use a local signing key for outbound task and messaging actions, which makes the skill medium risk rather than benign.
Confidence: 82%Severity: 58%
Audit Metadata