mixture-of-experts

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated auditing purpose is broadly coherent, and it does not seek credentials or obvious exfiltration paths, but the install model is a meaningful transitive-trust risk because it instructs the agent to load a third-party skill via `npx skills add`. Its broad review scope and subagent orchestration also increase indirect prompt-injection exposure. No confirmed malicious behavior is present, but the skill should be treated as medium/high risk due to external skill installation and agentic breadth.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Jul 30, 2026, 10:37 AM
Package URL
pkg:socket/skills-sh/arenukvern%2Fskill_steward%2Fmixture-of-experts%2F@0c2bb5e56c466636360a85b1d1dd642787977202f4889d046db758501270c84d
Security Audit — socket — mixture-of-experts