catador-pro
Warn
Audited by Socket on Mar 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core cupping analysis behavior is benign, but the skill's footprint expands into public web deployment and credentialed Cloudflare operations that are not strictly necessary for the stated purpose. Data flows go to official providers rather than obvious exfiltration endpoints, so this is not confirmed malware, but the automatic public deployment and credential scope make the skill medium risk overall.
Confidence: 88%Severity: 62%
Audit Metadata