akf-trust-metadata

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and commands are internally coherent for a metadata/provenance tool, but install trust is not established: it asks users to install external pip/npm packages tied to an individual/community publisher without proof that the package names, website, and repo are all officially linked. No direct credential theft or exfiltration is shown, so this is not confirmed malware, but it carries medium supply-chain risk.

Confidence: 77%Severity: 58%
Audit Metadata
Analyzed At
Apr 19, 2026, 05:03 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fakf-trust-metadata%2F@389be81c680e04787df9015bb1bc746f6890c628