Warn
Audited by Socket on Jul 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core capability matches the stated purpose, and there is no remote installer or obvious credential exfiltration path. However, the skill relies on full session cookies, can take real public actions, uses a loose /tmp script-discovery fallback, and the publisher admits the flow is not E2E-verified with limited independent documentation for the connector/cookie-capture path.
Confidence: 86%Severity: 56%
Audit Metadata