wiki
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its install path is not proportionate to the sensitivity of the data it handles. It asks the agent to clone and run an unverified personal GitHub project, then install and execute its dependencies before processing private notes and documents; that makes this a high supply-chain risk even without explicit exfiltration behavior.
Confidence: 87%Severity: 83%
Audit Metadata