customer-discovery
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core capability matches the stated purpose of customer research, and most data flows are proportionate. Risk comes from optional transitive companion skills and credential forwarding to locally referenced scripts with unclear provenance, plus broad ingestion of untrusted web content; this is not clearly malicious, but it exceeds a fully low-risk documentation/research skill.
Confidence: 84%Severity: 56%
Audit Metadata