industry-research
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities largely match its music-research purpose and its credential/data flow appears to target the vendor's official domains, but the undocumented provenance of the required `recoup` CLI prevents a benign classification. Main risk is moderate supply-chain uncertainty plus prompt-injection exposure from researching arbitrary web content.
Confidence: 79%Severity: 58%
Audit Metadata