health
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and capabilities are mostly coherent for a local health-data substrate, and the documented data flows largely match that purpose. The main issue is install trust: the core package/CLI provenance is not verifiable from the supplied evidence, while installation depends on an unseen local installer script that also links agent files. That makes the skill higher-risk than its polished privacy posture suggests, but not clearly malicious.
Confidence: 86%Severity: 74%
Audit Metadata