oracle-soul-sync-calibrate-update

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The analyzed fragment describes a coherent update/maintenance workflow for a composite AI skill, but it introduces supply-chain risk by auto-fetching and installing code from a remote GitHub source without explicit verification or strong integrity checks. It is suspicious rather than clearly benign due to the potential for installing tampered code, and it lacks safeguards (signing, pinned versions, confirmations). Recommend adding integrity checks (SHA/PGP), explicit user prompts before upgrades, and fallback/rollback capabilities to reduce supply-chain risk.

Confidence: 68%Severity: 65%
Audit Metadata
Analyzed At
Feb 20, 2026, 05:00 AM
Package URL
pkg:socket/skills-sh/soul-brews-studio%2Foracle-skills-cli%2Foracle-soul-sync-calibrate-update%2F@818527a4c12e898a85b4677606855a7000cda70b