opc-community-writer
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The stated purpose is coherent for a content-writing skill, but its execution footprint is broader than necessary because it grants wildcard npm/npx/bun/node command access and requires running unseen local setup scripts. No direct credential harvesting or exfiltration is visible, yet supply-chain trust is only partially established and external-content research plus exec/write capability raises moderate agent-safety risk.
Confidence: 83%Severity: 64%
Audit Metadata