mixture-of-experts
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated auditing purpose is broadly coherent, and it does not seek credentials or obvious exfiltration paths, but the install model is a meaningful transitive-trust risk because it instructs the agent to load a third-party skill via `npx skills add`. Its broad review scope and subagent orchestration also increase indirect prompt-injection exposure. No confirmed malicious behavior is present, but the skill should be treated as medium/high risk due to external skill installation and agentic breadth.
Confidence: 82%Severity: 74%
Audit Metadata