audit

Warn

Audited by Socket on Oct 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is coherent as an EVM audit workflow, but it is still high risk because it grants an AI agent offensive security review capability, loads additional mutable remote instructions from a personal GitHub repo, and can take external actions by filing GitHub issues. I found no strong evidence of malware or credential theft, but the transitive remote-instruction model and security-audit purpose materially raise risk.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Oct 8, 2026, 05:35 AM
Package URL
pkg:socket/skills-sh/austintgriffith%2Fethskills%2Faudit%2F@ef5fe8b044a772fa74bab7b1cae9ca5c2d662c5d58c5b0de664530c588c97dce