talent-sourcing
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core behavior matches talent sourcing and the Nimble dependency appears same-org and officially documented, so there is no strong sign of malware or credential theft. Risk comes from broad agent permissions, bypassPermissions sub-agents, external CLI/API dependency, and processing untrusted web content with write/exec capability; the unspecified distribution step adds uncertainty.
Confidence: 86%Severity: 56%
Audit Metadata