accessibility

Warn

Audited by Socket on Jul 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated accessibility purpose is coherent, but it instructs transitive installation of third-party skills through a local wrapper whose provenance and fetch behavior are not visible. No direct credential theft or exfiltration is evident in the provided content, so this is not confirmed malware, but the trust chain expansion makes it a meaningful security risk.

Confidence: 87%Severity: 67%
Audit Metadata
Analyzed At
Jul 5, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/alvarovillalbaa%2Fplugins%2Faccessibility%2F@e2f54ad8142ab05db9b0e9780b391903ba2ca32f12c6cdf1a8649bb0ff3ad6a8
Security Audit — socket — accessibility