skill-stocktake
Warn
Audited by Socket on Jun 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and directory access are broadly coherent for a local stocktake tool, and there is no clear credential theft or malicious exfiltration path. However, it executes unseen local bash scripts and feeds untrusted skill content into a general-purpose subagent, creating moderate supply-chain and indirect prompt-injection risk that cannot be dismissed from the provided text alone.
Confidence: 100%Severity: 60%
Audit Metadata