cekura-coordinator

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The coordinator’s stated purpose is coherent and mostly benign, but the surrounding documented workflow introduces moderate trust risk: it can route into other skills and, for some MCP setups, relies on third-party mcp-remote that may receive Cekura API keys. This is not confirmed malware and does not show incompatible behavior inside the skill itself, but the transitive trust chain and credential-forwarding pattern make it riskier than a simple help/router skill.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 10, 2026, 08:06 PM
Package URL
pkg:socket/skills-sh/cekura-ai%2Fcekura-skills%2Fcekura-coordinator%2F@d75734e8c68ee4073be5a4069ff40d0944cb7964