digest
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The digesting and logging behavior broadly fits the claimed purpose, and the xAI endpoint is official, but the trust boundary is broken by `./secretcurl`: an unverifiable local executable receives `XAI_API_KEY` and performs the authenticated call. Combined with autonomous notification and ingestion of untrusted external content, this makes the skill high risk despite a plausible use case.
Confidence: 90%Severity: 86%
Audit Metadata