domain-context
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The main documentation behavior is coherent and low-risk, but the explicit instruction to install companion skills from a third-party repository introduces a disproportionate transitive trust risk. This is not confirmed malware, but it should be treated as a medium-risk skill because it expands agent behavior beyond local glossary/ADR maintenance.
Confidence: 90%Severity: 58%
Audit Metadata