cook-the-blog
Warn
Audited by Socket on Apr 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core blog-writing purpose is plausible, but the skill is overpowered: it researches untrusted web content, executes external scripts/builds, uploads files, pushes directly to a repository, and sends mandatory email summaries. The data flows are not clearly malicious, yet the scope and autonomy are disproportionate for a writing skill and create meaningful supply-chain, prompt-injection, and credential-exposure risk.
Confidence: 91%Severity: 84%
Audit Metadata