tool-inventory-init
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the visible skill is mostly coherent for local inventory bootstrapping and does not show explicit credential theft or remote exfiltration, but it relies heavily on transitive internal skills/plugins that are not verifiable from the evidence. The main risk is opaque delegated behavior rather than the local bootstrap step itself.
Confidence: 79%Severity: 56%
Audit Metadata