swain-helm

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated bridge-management behavior is broadly coherent, but its real trust boundary is a local swain-helm binary that could not be independently verified. Because that opaque executable appears to receive 1Password/chat/opencode credentials and control persistent processes, the overall risk is high even without direct evidence of exfiltration.

Confidence: 85%Severity: 84%
Audit Metadata
Analyzed At
May 4, 2026, 07:09 PM
Package URL
pkg:socket/skills-sh/cristoslc%2Fswain%2Fswain-helm%2F@f090719e68c16542c918417d6ef19a3db046ccb4