base
Warn
Audited by Socket on Jul 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. Most of the skill is benign process guidance, but the credential-management section is disproportionate for an always-loaded base skill: it instructs the agent to ask for a centralized secrets file, parse multiple API keys, validate them, and write them into project .env files. That broad secret-handling behavior does not cleanly fit a universal coding/TDD foundation skill, even though there is no direct malware, exfiltration endpoint, or remote installer present.
Confidence: 90%Severity: 58%
Audit Metadata