counselors

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the overall workflow is purpose-aligned, but the skill reads raw dotenv files, forwards credentials to a third-party CLI, and sends local code/diffs to multiple external AI services. The main concern is disproportionate credential and data exposure for a review helper, not confirmed malware.

Confidence: 82%Severity: 71%
Audit Metadata
Analyzed At
Mar 13, 2026, 01:08 AM
Package URL
pkg:socket/skills-sh/skinnyandbald%2Ffish-skills%2Fcounselors%2F@4cee5f9039ff05bf21e6a48ef9780ba92670a3c8