ravi

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent for an agent identity provider, and the install path appears same-org and publicly sourced, so this is not confirmed malware. However, it centralizes highly sensitive data and real-world communication actions, stores auth keys locally, forwards third-party secrets into Ravi, and instructs routine feedback emails that may leak workflow details; this makes the overall security exposure medium-high even though the purpose matches the capabilities.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 10, 2026, 09:23 PM
Package URL
pkg:socket/skills-sh/ravi-hq%2Fravi-skills%2Fravi%2F@ef3827fa9ab6e69b1a03e2ef593614a6fe390bbd