GPG Encryption and Key Management Agent
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The stated GPG capabilities are coherent with the skill’s purpose, and the described data flows to GnuPG and public keyservers are proportionate. The main concern is install trust: distribution is indirect via a transitive skill installer with unpinned execution and an unverified publisher/repo relationship, making this suspicious rather than malicious.
Confidence: 86%Severity: 64%
Audit Metadata