fine-dust-location
Audited by Socket on Sep 17, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the claimed purpose is benign, but the skill is mostly a thin loader for mutable remote instructions delivered by a same-org npm CLI and GitHub content. No direct credential theft or clearly malicious endpoint is shown here, but the indirection and runtime deferral make the skill less trustworthy and less auditable than a self-contained weather/air-quality lookup skill should be.
The code is primarily a legitimate air-quality reporting client, with no clear malware behavior or obfuscation. Security concerns are material: API keys are sent in plaintext HTTP query strings, and location inputs are sent by default to an external configurable proxy. Use HTTPS-only endpoints, avoid putting secrets in URLs, validate or restrict proxy destinations, and confirm the apparent syntax error is only a transcription issue.