yoetz
Warn
Audited by Socket on Jul 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s core capabilities broadly match its stated purpose as an LLM council and browser gateway, but its footprint is large: multi-source installs, transitive skill installation, provider-key use through an external CLI, and browser automation against a logged-in ChatGPT session. This looks more like a high-risk agent automation skill than obvious malware, with the main concerns being supply-chain breadth, transitive trust, and prompt-injection/autonomous browser-action exposure.
Confidence: 86%Severity: 72%
Audit Metadata