scorecard
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is legitimate, but the skill routes users to a third-party X-CMD wrapper instead of the official OpenSSF Scorecard tooling. The main risk is supply-chain and transitive trust from remote-script installation and mediated API access, not confirmed malicious behavior.
Confidence: 90%Severity: 64%
Audit Metadata