c-level-advisor
Audited by Socket on Sep 3, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The skill’s stated purpose is coherent and its visible capabilities are mostly local and proportionate, but provenance is weak: public distribution shows inconsistent publisher identity, no authoritative release trail, and a transitive reference to another skill/resource. With no credential access or network exfiltration in the supplied content, this is not malware, but it carries moderate trust and supply-chain risk.
SUSPICIOUS. The visible skill behavior is mostly coherent and locally scoped for executive advisory, but the broader repo distribution introduces medium supply-chain risk through unpinned remote script execution and a third-party mirror domain. No evidence here shows credential theft, hidden exfiltration, or malicious pre-execution behavior.