vmware-engineer

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
vmware-engineer/SKILL.md

SUSPICIOUS. The skill’s functional content is benign advisory documentation, but its installation model is weak: it asks agents to ingest remote instructions from a mutable third-party GitHub raw URL and to install/load the skill across agent platforms. I found no credential harvesting, malware behavior, or disproportionate system access, so the main concern is supply-chain and transitive trust rather than malicious payloads.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:25 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Fvmware-engineer%2F@662c86694027a2e2623e5e0cd1cff9c2b66b89c0