context-hub
Warn
Audited by Socket on May 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the skill expands trust to an external CLI and remote content, then instructs the agent to treat that content as authoritative. The biggest issue is indirect prompt-injection/transitive trust, plus default outbound feedback posting; there is no clear evidence of credential theft or malware.
Confidence: 81%Severity: 66%
Audit Metadata