viboscope

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose is plausible, but its actual footprint is broader than necessary: mutable remote installation, weak provenance, raw credential-file handling, and transmission of local workspace/conversation context to a remote matching API. Data flows are first-party to viboscope.com rather than an obvious exfiltration service, so this is not confirmed malware, but it is a high-risk skill for privacy and supply-chain reasons.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Mar 30, 2026, 03:30 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fviboscope%2F@e50284cb6c5b536f9606cd724598cea9e08b95d0