researcher
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent for a repo-analysis skill, but its footprint relies on an undocumented external runtime and processes arbitrary remote repositories, creating meaningful supply-chain and prompt-injection risk. No clear credential harvesting or overt malicious behavior is shown, so this looks more like a high-risk/unverifiable research skill than confirmed malware.
Confidence: 81%Severity: 76%
Audit Metadata