cohesivity
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS leaning benign. The core data flows and capabilities fit an infrastructure skill, and secrets are sent only to official Cohesivity endpoints. The main concern is install/trust inconsistency: the manual plugin installation path references buildwithclaude/davepoon rather than a clearly verifiable Cohesivity-owned publisher, creating transitive trust and supply-chain risk. No clear credential harvesting or malicious exfiltration is evident.
Confidence: 86%Severity: 62%
Audit Metadata