council

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow mostly matches its stated purpose, but it relies on an unverifiable `council` CLI and combines untrusted web research with multi-agent local file writes. There is no clear credential harvesting or exfiltration behavior, but install trust and external-content-to-write-action risk are high enough to warrant caution.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
May 6, 2026, 06:22 AM
Package URL
pkg:socket/skills-sh/tyrchen%2Fclaude-skills%2Fcouncil%2F@f09afc16a6cac46f397a8d2a09b9e1023102a2b9