join
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s behavior mostly matches its stated purpose: it asks for the tenant key, calls a cloud identity endpoint, and writes local config. The main concern is install trust: it executes an unpinned package that directly receives the credential, and the exact @catalyst-cloud/catalyst-skills package provenance was not fully verifiable from the provided evidence. No clear malicious exfiltration is shown, but the credential-forwarding and partially unverifiable package trust chain make this higher risk than a typical setup helper.
Confidence: 80%Severity: 62%
Audit Metadata