implementing-plans
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core implementation/tracking behavior is broadly coherent and local, but the skill expands its trust boundary by directing the agent to use third-party `rpikit` skills and by allowing web-research in a workflow that can also write files and execute commands. No direct credential harvesting or exfiltration is present, so this is better classified as a medium-risk vulnerable skill rather than malware.
Confidence: 87%Severity: 58%
Audit Metadata