gymcam-analytics
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the skill’s trust model is weak: it installs and executes unpinned MCP code from an unverified personal GitHub repo, then forwards an API key to that code. This is disproportionate supply-chain and credential-forwarding risk for a skill that could otherwise use a verified package or documented official installer.
Confidence: 86%Severity: 82%
Audit Metadata