capability-activation
Fail
Audited by Socket on Feb 15, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The document is not executable malware but represents a high-risk policy that materially increases software supply-chain and privacy risk. By mandating frequent, unconditional invocation of external skill modules and forbidding alternative inspection, it widens the channel for malicious or privacy-invasive skills to be loaded and followed. Without strong platform safeguards (signed skill provenance, sandboxed execution, least-privilege data exposure, explicit user consent, and auditable logs), this policy should be treated as dangerous and subject to review, restriction, or removal.
Confidence: 98%
Audit Metadata