foundation-models
Fail
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The FoundationModels skill appears coherently aligned with its stated purpose of on-device LLM integration, including structured output and tool calling. There are no indicators of insecure downloads, credential harvesting, or untrusted data exfiltration. The data flows are contained within on-device processing and explicit tool invocations, with results surfaced to the UI. Overall risk is low to moderate (benign), with no evident security vulnerabilities in the provided snippet. Consider validating any real-world tool implementations for network access controls and ensuring explicit user consent for tool usage in production apps.
Confidence: 98%
Audit Metadata