last30days

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent, and the OpenAI/xAI capabilities are plausible, but the skill's main executable is a community-owned, unverifiable local script that receives API keys. That credential-forwarding path and lack of provenance make the overall risk high even without confirmed malicious behavior.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Mar 22, 2026, 11:11 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Flast30days%2F@f6d06a86d8da9a95a83324d15c2017fd3f06f1f4