gm-skill

Warn

Audited by Socket on May 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated purpose: a local Plugkit-backed state machine that writes and reads spool files. The main risk is install/execution trust: it starts an unpinned external package (`gm-plugkit@latest`) as a silent background process, and the skill does not provide enough provenance to verify that package as the official same-publisher runtime. No strong signs of credential theft or intentional exfiltration are present in the skill text itself, but the remote package dependency makes this medium-risk and better classified as suspicious than fully benign.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
May 22, 2026, 11:17 AM
Package URL
pkg:socket/skills-sh/AnEntrypoint%2Fgm%2Fgm-skill%2F@9a446eed64a71cd46578b150594ebd2f1652e8e0
Security Audit — socket — gm-skill