review-demos
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core workflow matches the stated purpose, and most network endpoints are same-org psquared.dev services, but the skill is high-trust: it reads local secrets, consumes untrusted web content, and can autonomously publish agents, mutate CRM records, and run direct SQL updates. The main concern is overbroad write capability and prompt-injection risk rather than confirmed malware.
Confidence: 85%Severity: 67%
Audit Metadata