context-hub

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill expands trust to an external CLI and remote content, then instructs the agent to treat that content as authoritative. The biggest issue is indirect prompt-injection/transitive trust, plus default outbound feedback posting; there is no clear evidence of credential theft or malware.

Confidence: 81%Severity: 66%
Audit Metadata
Analyzed At
May 6, 2026, 10:49 PM
Package URL
pkg:socket/skills-sh/andrewyng%2Fcontext-hub-skill%2Fcontext-hub%2F@3723a37079978ac480f5288db226bac454adf239