agno
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose and examples are broadly coherent with Agno development, and the core Agno install path is legitimate. The main risk is documentation that encourages running third-party MCP servers via uvx/npx and forwarding environment variables/API keys into those external processes; this is a real supply-chain and credential-forwarding concern, but not confirmed malicious behavior in the skill itself.
Confidence: 89%Severity: 56%
Audit Metadata