trace

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core capabilities mostly align with its stated discovery purpose, and it uses legitimate tools, but it expands read scope across multiple local repos, clones arbitrary user-supplied repos, and forwards findings to an unspecified Oracle MCP service. The main concerns are moderate data-flow opacity and prompt-injection exposure from searching untrusted repo and GitHub content with write capability.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Mar 14, 2026, 02:37 AM
Package URL
pkg:socket/skills-sh/soul-brews-studio%2Foracle-skills-cli%2Ftrace%2F@66cf0e932d167b02938ef50b18583ef115faacdb