c-level-advisor

Warn

Audited by Socket on Sep 3, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
cpo-advisor/SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent and its visible capabilities are mostly local and proportionate, but provenance is weak: public distribution shows inconsistent publisher identity, no authoritative release trail, and a transitive reference to another skill/resource. With no credential access or network exfiltration in the supplied content, this is not malware, but it carries moderate trust and supply-chain risk.

Confidence: 85%Severity: 52%
AnomalyLOW
SKILL.md

SUSPICIOUS. The visible skill behavior is mostly coherent and locally scoped for executive advisory, but the broader repo distribution introduces medium supply-chain risk through unpinned remote script execution and a third-party mirror domain. No evidence here shows credential theft, hidden exfiltration, or malicious pre-execution behavior.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Sep 3, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/afaizalam2003%2Fmaster-claude-skill%2Fc-level-advisor%2F@fcc4cc8a453a59553b3fb592db9fdd068e3922e2816dc962887fc75db72081c4
Security Audit — socket — c-level-advisor