feedback
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is plausible and the upload behavior matches its description, but it requires an externally managed `asta` CLI with unverified public provenance and sends local content to an undisclosed private endpoint. No direct credential theft or overtly malicious behavior is shown, yet the opaque binary/deployment path and broad file permissions make the overall risk high enough to avoid a benign classification.
Confidence: 83%Severity: 78%
Audit Metadata