accessibility
Warn
Audited by Socket on Jul 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated accessibility purpose is coherent, but it instructs transitive installation of third-party skills through a local wrapper whose provenance and fetch behavior are not visible. No direct credential theft or exfiltration is evident in the provided content, so this is not confirmed malware, but the trust chain expansion makes it a meaningful security risk.
Confidence: 87%Severity: 67%
Audit Metadata