sbti-test

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The quiz logic itself is benign, but the skill’s optional sharing feature introduces a custom deployment chain that is not publicly verifiable and is disproportionate to the stated purpose. This looks more like elevated supply-chain and third-party data-flow risk than confirmed malware.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:38 AM
Package URL
pkg:socket/skills-sh/nexu-io%2Fsbti-skill%2Fsbti-test%2F@43763388268275fcc1990ad0ee809468dbf5b899