content-pipeline
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core content-pipeline behavior is broadly aligned with its stated purpose and the human approval gate is a strong safety control, but the analytics path is under-specified: routing via an unnamed FastAPI proxy creates medium risk because credentials and analytics data may traverse a third-party intermediary rather than official APIs. The optional handoff to a WordPress skill also adds transitive trust. No evidence of malware, obfuscation, or malicious install behavior is present in the provided skill text.
Confidence: 100%Severity: 60%
Audit Metadata