acomm-receive

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated behavior is coherent and narrowly scoped, and no direct credential theft or external exfiltration is shown. However, it requires opaque local binaries (`acomm`, `yuiclaw`) whose provenance is not verifiable from the evidence, which creates a mandatory high supply-chain risk floor; additionally, it passes untrusted incoming text straight into downstream automation via stdout.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
Mar 14, 2026, 05:10 PM
Package URL
pkg:socket/skills-sh/yuiseki%2Fai-secretary%2Facomm-receive%2F@81187456f123e7af19c669e2161e11f8e2f26193