audit
Warn
Audited by Socket on Oct 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is coherent as an EVM audit workflow, but it is still high risk because it grants an AI agent offensive security review capability, loads additional mutable remote instructions from a personal GitHub repo, and can take external actions by filing GitHub issues. I found no strong evidence of malware or credential theft, but the transitive remote-instruction model and security-audit purpose materially raise risk.
Confidence: 89%Severity: 78%
Audit Metadata