audit-prototype

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core audit behavior and local file access are proportionate to the stated purpose, but the skill relies on an unverifiable nvst CLI and unnamed external skills without clear provenance. There is no direct evidence of credential theft or overt exfiltration, yet the unresolved trust chain makes the skill medium-high risk overall.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:50 AM
Package URL
pkg:socket/skills-sh/quinteroac%2Fnerds-vibecoding-survivor-toolkit%2Faudit-prototype%2F@9d7bf50f00a36d35d6d5ef3b197d82c9c9f0ff9e