rlama

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core local-document RAG functionality is coherent, but the skill overstates privacy: it claims fully local/offline operation while also supporting cloud providers, arbitrary custom endpoints, remote Ollama hosts, and web crawling. Install trust is medium-risk due to an unpinned raw GitHub installer and mutable release binaries from a personal repo. Not confirmed malware, but the privacy and data-flow claims are materially inconsistent with the actual capability footprint.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:48 AM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Frlama%2F@d4d89d96678f971240a7ed9f4b9f8432eb429899