NYC

capability-activation

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document is not executable malware but represents a high-risk policy that materially increases software supply-chain and privacy risk. By mandating frequent, unconditional invocation of external skill modules and forbidding alternative inspection, it widens the channel for malicious or privacy-invasive skills to be loaded and followed. Without strong platform safeguards (signed skill provenance, sandboxed execution, least-privilege data exposure, explicit user consent, and auditable logs), this policy should be treated as dangerous and subject to review, restriction, or removal.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:02 PM
Package URL
pkg:socket/skills-sh/qodex-ai%2Fai-agent-skills%2Fcapability-activation%2F@29b53bce06c9fda0fc4867e20f08eb25c5857b11