GPG Encryption and Key Management Agent

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The stated GPG capabilities are coherent with the skill’s purpose, and the described data flows to GnuPG and public keyservers are proportionate. The main concern is install trust: distribution is indirect via a transitive skill installer with unpinned execution and an unverified publisher/repo relationship, making this suspicious rather than malicious.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:35 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fgpg-encryption-and-key-management-agent%2F@6f660a046a37e4c9034eba170e511495be44d6b3