learn
Warn
Audited by Socket on Jul 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core learning workflow is coherent, but the skill expands its trust boundary by recommending a third-party NotebookLM CLI and a separate GitHub-hosted skill, while also fetching arbitrary web content and writing persistent local files. No clear exfiltration or malicious payload is present, but the transitive-install and external-tool trust model is broader than necessary for a study assistant.
Confidence: 85%Severity: 66%
Audit Metadata