grounding-lite
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core purpose and Google API data flow are coherent, but it introduces an unnecessary third-party CLI (mcporter) that receives the API key before sending requests to Google. This is not strong evidence of malware or exfiltration, yet the extra credential-forwarding layer and unpinned third-party install make it medium risk rather than benign.
Confidence: 89%Severity: 53%
Audit Metadata