trailmark-summary

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior largely matches its stated purpose and avoids installs, credential access, and third-party routing, but it relies on an unverifiable external `trailmark` CLI. That unresolved provenance makes the overall footprint higher-risk than a normal documentation or local-analysis skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 31, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Ftrailmark-summary%2F@1f30ed58ec1b0645536ccda8ab8a241959d094bc