interrogate-me
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s behavior is broadly consistent with its stated purpose: interrogate the user, inspect the codebase, and update local docs. The main concern is install trust, not in-skill behavior: it is installed via transitive `npx skills add` from a personal GitHub repo with weak provenance and no clear signed release trail. No credential harvesting, hidden network exfiltration, or disproportionate permissions are evident from the skill content itself.
Confidence: 89%Severity: 56%
Audit Metadata