cat-check

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a UI-vibes auditing skill, and there is no clear credential theft or exfiltration behavior. However, it requires executing a local `glimpse` project through `uv run`, and that tool's provenance is not verifiable from the skill text; combined with external page fetching and shell-based execution, this creates medium supply-chain and prompt-injection risk disproportionate to a purely advisory design-review skill.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:19 AM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fgroveengine%2Fcat-check%2F@99e08ea6e234bfd4eb3eb444fcd4498c97c4b700
Security Audit — socket — cat-check