loci-post-edit

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill relies on unverifiable local analysis binaries/scripts and an undisclosed MCP backend. No clear credential theft or overtly malicious behavior is shown, yet install/execution trust and endpoint transparency are insufficient for a benign rating.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 07:49 AM
Package URL
pkg:socket/skills-sh/auroralabs-loci%2Floci-claude%2Floci-post-edit%2F@f51c4ea23de3c2e52eb381dedbc6d453393ce328
Security Audit — socket — loci-post-edit