riff

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent for parallel app ideation, but it executes bundled local scripts whose contents are not visible, sends prompts through a local Claude CLI, and can auto-invoke other skills. No clear credential theft or exfiltration endpoint is present, so this is not confirmed malware, but the execution breadth and transitive-skill handoff make it medium risk.

Confidence: 82%Severity: 52%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:26 PM
Package URL
pkg:socket/skills-sh/popmechanic%2Fvibes-cli%2Friff%2F@ab050fb76a9712f2a221a3cb7b7cd37b746da190