validator-commit
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is purpose-aligned and shows no direct exfiltration or overtly malicious behavior, but it depends on an unverifiable external CLI (`agent-validate`) and delegates to other local skills. That makes it high risk from a trust and provenance standpoint, though better classified as suspicious/vulnerable rather than malicious.
Confidence: 87%Severity: 75%
Audit Metadata