last30days
Warn
Audited by Socket on Mar 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, and the OpenAI/xAI capabilities are plausible, but the skill's main executable is a community-owned, unverifiable local script that receives API keys. That credential-forwarding path and lack of provenance make the overall risk high even without confirmed malicious behavior.
Confidence: 91%Severity: 86%
Audit Metadata