pro

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The visible skill is mostly coherent with local self-tracking and session recovery, but it introduces undisclosed remote config refresh and telemetry flows that cannot be validated from the provided text. No malicious installer or clear credential theft is shown, yet the hidden outbound behavior is disproportionate enough to warrant caution.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/tanweai%2Fpua%2Fpro%2F@4930ef5d6da212afd68b87fffe7d301da00764f6