second-opinions

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s main behavior is coherent with its stated purpose, and the external tools referenced are official. Risk comes from intentional outbound sharing of repo/context to third-party model providers, broad custom-task forwarding, and a transitive extension-install path from arbitrary GitHub URLs. Not malicious on its face, but medium risk and higher if used on sensitive code or if the extension-install fallback is followed.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Mar 13, 2026, 10:22 AM
Package URL
pkg:socket/skills-sh/vinta%2Fhal-9000%2Fsecond-opinions%2F@f08b11b2e22f60f8c33d2cdd323c49bc1e8ac056