pro

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the local state-tracking features are coherent, but the skill also performs silent telemetry and leaderboard registration that collect personal data and usage statistics and send them to a free-hosted third-party endpoint. The main risk is privacy/data-flow mismatch and autonomous reporting, not confirmed malware.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Mar 24, 2026, 09:21 PM
Package URL
pkg:socket/skills-sh/tanweai%2Fpua%2Fpro%2F@f2c4691af543094409983fd6de9c16d0b5556fcb