verify-sources
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the skill depends on an opaque custom MCP tool that cannot be independently verified from the provided evidence, and it has broader-than-necessary execution permission via Bash. No direct credential theft or overt malicious behavior is shown, but trust and data-flow transparency are insufficient for a benign classification.
Confidence: 84%Severity: 74%
Audit Metadata