comment-funnel
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely purpose-aligned and uses same-org Upload-Post docs/API endpoints, with no installer or obvious malware signals. Risk is driven by third-party credential forwarding, unverified persistent monitor endpoints, and autonomous outbound DM actions on the user's behalf.
Confidence: 87%Severity: 61%
Audit Metadata