core
Warn
Audited by Socket on Jun 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally consistent for a terminal-control API guide and shows no overt exfiltration or malicious installer behavior, but it grants very broad live terminal observation/control and input capture. The main concern is high operational power plus limited independent provenance evidence for the underlying wsh tool, not clear malicious intent.
Confidence: 100%Severity: 60%
Audit Metadata