ai-script
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS fit. The stated purpose matches the broad media/search capabilities, but the trust boundary is weak: the skill relies on an unverifiable local wrapper repo that sources `~/.zshrc` and then forwards user data and API credentials to multiple external services. No overt exfiltration or hidden behavior is shown in the skill text, but the install/provenance gap and credential-forwarding to a local black-box CLI make this high risk.
Confidence: 84%Severity: 82%
Audit Metadata