track-generation
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s stated purpose is coherent with its genomics workflow, and it does not request credentials or obviously route data to third parties. However, the actual execution depends on opaque MCP tools with no verifiable publisher/source/release trail in the skill, so this is best classified as SUSPICIOUS due to supply-chain trust rather than confirmed malicious behavior.
Confidence: 81%Severity: 72%
Audit Metadata