oracle
Warn
Audited by Socket on May 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s main behavior matches its stated purpose, and installation is via an official registry under the same publisher identity, so this is not clearly malicious. However, it routes selected code and prompts through a third-party CLI, forwards provider credentials to that CLI, supports custom proxy/base-url endpoints, and can automate logged-in browser AI sessions; those combined data-flow and credential-forwarding risks make it higher-risk than a simple documentation skill.
Confidence: 86%Severity: 64%
Audit Metadata