mention-radar
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose and official API usage are mostly coherent, and there is no clear malicious data diversion. However, its core execution depends on opaque local helpers (especially ./secretcurl receiving XAI_API_KEY), which makes credential handling and runtime behavior insufficiently verifiable; that pushes overall risk above benign.
Confidence: 85%Severity: 72%
Audit Metadata