skill

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior is mostly aligned with its stated purpose, and the `sundial-hub` CLI appears to be the official distribution path. The main risk is transitive trust: it installs and publishes skills through an external ecosystem, giving third-party skills a path into the agent environment. This is not confirmed malware, but it carries meaningful supply-chain and autonomy risk.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 29, 2026, 11:21 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fskills%2Fskill%2F@ad2b5e8532eb0b12a2868cd08fb81b934a1a3577