content-engine
Warn
Audited by Socket on Jul 1, 2026
2 alerts found:
AnomalySecurityAnomalyskills/content-engine-autopilot/SKILL.md
LOWAnomalyLOW
skills/content-engine-autopilot/SKILL.md
SUSPICIOUS: The core browser-orchestration purpose is coherent, but the install trust is not. The skill depends on a third-party browser automation CLI with a publisher mismatch in the instructions, then uses it to manage persistent authenticated sessions for multiple external services. No clear malicious exfiltration is shown, but the provenance inconsistency plus credential-like session handling make the skill medium/high risk.
Confidence: 84%Severity: 63%
Securityskills/content-engine-loop/SKILL.md
MEDIUMSecurityMEDIUM
skills/content-engine-loop/SKILL.md
Audit Metadata