propose-hypotheses

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow purpose and local file operations are coherent, and there is no direct credential theft or exfiltration in the skill text. The main risk is transitive trust in an externally supplied `fpf-agent` with unclear canonical ownership and unpinned install provenance, which is disproportionate enough to keep this out of BENIGN but not strong enough for MALICIOUS.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:11 AM
Package URL
pkg:socket/skills-sh/neolabhq%2Fcontext-engineering-kit%2Fpropose-hypotheses%2F@1ab29085945c5ffad2f93ca0e22bfa3e9e43a18b6f3d1922c17a2de7d0735ce1
Security Audit — socket — propose-hypotheses