propose-hypotheses
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the workflow purpose and local file operations are coherent, and there is no direct credential theft or exfiltration in the skill text. The main risk is transitive trust in an externally supplied `fpf-agent` with unclear canonical ownership and unpinned install provenance, which is disproportionate enough to keep this out of BENIGN but not strong enough for MALICIOUS.
Confidence: 82%Severity: 56%
Audit Metadata