add-ollama-tool

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint appears coherent with its stated purpose: it exposes locally hosted Ollama models via an MCP server to enable efficient on-device task processing for the container agent. Data flows are localized (agent -> MCP -> Ollama -> MCP -> agent) with no evident credential handling or external exfiltration. The main risk stems from potential supply-chain concerns if any binaries or scripts are sourced from untrusted channels; otherwise, the approach is proportionate and low-risk for a local-model integration.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fadd-ollama-tool%2F@a093e5c51abe167bea81b60c7f7d1360615619a0