shiplog
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose and most capabilities are coherent for a cross-repo release recap, and it uses official GitHub and xAI endpoints. The main risk is install/execution trust: core functionality relies on unverifiable local executables, and one of them receives XAI_API_KEY. That creates a high credential-forwarding and supply-chain risk even though the stated purpose is legitimate.
Confidence: 88%Severity: 82%
Audit Metadata