security-review
Warn
Audited by Socket on May 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is internally coherent for a security-audit purpose, and most tooling is legitimate and proportionate. However, it equips an AI agent with security-assessment capabilities and may route scan data and API tokens through third-party vendor CLIs (Safety, Snyk), which raises risk despite no clear evidence of credential theft or deceptive behavior.
Confidence: 88%Severity: 61%
Audit Metadata