procedural-fish-render
Warn
Audited by Socket on Apr 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated capability matches the skill’s purpose, but its core behavior is to fetch and run project code from a fixed repository that is currently not publicly reachable or verifiable, using a mutable branch. That makes the install/execution trust disproportionately weak for a rendering helper even without direct evidence of credential theft.
Confidence: 88%Severity: 82%
Audit Metadata