rightstack
Warn
Audited by Socket on Aug 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and read-only behavior are mostly coherent, but it relies on an externally sourced RightStack package/service whose public provenance could not be verified from the provided evidence. No clear credential theft or malicious action appears, yet the unverifiable dependency and opaque network/data path make this a high supply-chain trust risk.
Confidence: 79%Severity: 78%
Audit Metadata