bfs-ai-script
Warn
Audited by Socket on Jul 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the broad AI/media/search functionality, but the skill routes user data and API keys through a local opaque wrapper that sources `~/.zshrc` and invokes an unverifiable CLI/repo. The main risks are supply-chain trust, credential forwarding, and untrusted-content-to-LLM flow rather than confirmed malicious intent.
Confidence: 83%Severity: 84%
Audit Metadata