acommons

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent with an AI-usage analytics product, and its only named API endpoint matches the publisher's domain, but it installs persistence, collects telemetry across many local AI tools, stores auth material locally, and implies ongoing uploads via undocumented local scripts/API behavior. Not overtly malicious, but higher-trust than a simple local stats viewer and warrants caution.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
Apr 18, 2026, 02:50 AM
Package URL
pkg:socket/skills-sh/Phlegonlabs%2Fagentic-commons%2Facommons%2F@bc25fa86541452b290858524798fe0bfbff50aae