import-track

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's visible behavior is coherent and narrowly scoped to local file organization, with no explicit credential handling or network exfiltration. However, it requires an unverifiable external MCP tool, so trust in path resolution is delegated to opaque third-party code; this makes the skill medium-high risk despite otherwise benign purpose alignment.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 27, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/bitwize-music-studio%2Fclaude-ai-music-skills%2Fimport-track%2F@12cda4b7eac102950798c47d1f8e22652ae89c16