rabbit-inspect

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose largely matches the behavior: screenshot-based first-impression testing and optional issue creation are coherent. The main concern is install/execution trust: the skill mandates a repo-local `glimpse` CLI executed through `uv run --project`, but the tool's provenance, lock state, and dependency chain are not established here. No clear credential theft, exfiltration endpoint, or fundamentally incompatible capability is present, so this is not malicious, but the unresolved local-tool supply-chain risk and untrusted-content processing keep it above benign.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fgroveengine%2Frabbit-inspect%2F@eaa2c4e0e2730be1d445cba21f78b2c22990361a
Security Audit — socket — rabbit-inspect