issue-review
Warn
Audited by Socket on May 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The install sources and platform API routing are mostly legitimate and aligned with the stated purpose, but the skill is high-risk because it autonomously posts on the user's behalf and combines untrusted external content with repo inspection and sub-agent execution. The main concern is not malware but disproportionate autonomy and prompt-injection/data-leak exposure for an analysis skill.
Confidence: 89%Severity: 76%
Audit Metadata