ito-inference
Warn
Audited by Socket on Aug 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent and its requested booking context is proportionate, but its core behavior depends on an unverifiable private Itô CLI that may receive authentication material and perform opaque network actions. There is no strong evidence of deliberate malware or exfiltration in the skill text itself, yet the dependency and credential-forwarding model create high security risk.
Confidence: 88%Severity: 82%
Audit Metadata