overvy
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core Overvy board operations are coherent with the stated purpose and use direct API calls, but the skill also authorizes high-impact autonomous development actions (git push and PR creation) and allows bearer-token redirection through an overridable API URL. This is not confirmed malware, but it is a medium/high-risk skill because its action scope exceeds simple board management and can publish changes externally.
Confidence: 85%Severity: 68%
Audit Metadata