lev-intake

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The lev-intake skill is coherently aligned with its stated purpose as a routing and intake orchestrator for diverse content types, delegating deep processing to specialized phases. The footprint is proportionate for a workflow controller, and Phase 1 does not solicit credentials or perform high-risk actions itself. However, there are notable gaps around trust provenance of external tools, explicit sandboxing/sanitization of external content, and concrete security controls during data flows. Until provenance and security controls are defined for upstream tools and phase transitions, the skill should be treated as SUSPICIOUS-leaning toward BENIGN with heightened scrutiny on tool provenance and data-sanitization practices.

Confidence: 98%Severity: 45%
Audit Metadata
Analyzed At
Mar 11, 2026, 11:16 AM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Flev-intake%2F@206c47a90267e40303ba0f115afafe346fca12a4