interview-simulator
Audited by Socket on Sep 18, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill’s purpose, credentials, and data flows are broadly consistent with building an interview simulator, but the installation trust chain is incomplete because the core application comes from an unspecified repo and then runs `npm install` with access to sensitive API keys. No clear malicious exfiltration or off-purpose behavior is shown, but the unverifiable repo/dependency path creates meaningful supply-chain risk.
No clear malicious behavior is present in the shown fragment. It implements legitimate interview-training functionality, but it processes and externally transmits highly sensitive user data and places untrusted transcript content directly into an AI prompt. Model output and database inputs require validation and authorization controls. The empty-weakness handling also contains a reliability defect. The assessment is limited because the file is truncated.