second-opinion

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill’s purpose mostly matches its behavior, and the primary installs appear official, but the Gemini path materially increases risk by using --yolo and optional extensions that can act without confirmation. This is not confirmed malware, but it is a higher-risk automation pattern with external code/data exposure and delegated tool execution.

Confidence: 85%Severity: 71%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Fsecond-opinion%2F@e9a24800b12ed40e4a0b28df9a90e0c3c654df13