kadath
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is coherent, but it has a large execution footprint: direct GitHub clone-and-run, Docker orchestration, credential capture, and autonomous agent execution with web-facing components. No clear evidence of credential theft or malicious exfiltration appears in the provided text, but the install trust and operational scope make it medium-to-high risk.
Confidence: 80%Severity: 71%
Audit Metadata