full-engagement-pipeline
Warn
Audited by Socket on Jul 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The accounting purpose largely matches the file access and local processing, but the skill includes an unspecified external `npx` extractor for highly sensitive financial documents. Because that external package is unnamed and unverifiable from the skill text, install trust and data-flow integrity are not adequate for the sensitivity of the task.
Confidence: 88%Severity: 82%
Audit Metadata