oracle

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main behavior matches its stated purpose, and installation is via an official registry under the same publisher identity, so this is not clearly malicious. However, it routes selected code and prompts through a third-party CLI, forwards provider credentials to that CLI, supports custom proxy/base-url endpoints, and can automate logged-in browser AI sessions; those combined data-flow and credential-forwarding risks make it higher-risk than a simple documentation skill.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
May 15, 2026, 10:45 AM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Foracle%2F@cbd8ac573a8213166fd7ff039a559d7db5a4c0e6
Security Audit — socket — oracle