devonthink
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Mostly coherent with a DEVONthink automation skill: the command set matches the stated purpose and there is no obvious credential theft or covert exfiltration. Main concerns are transitive plugin/skill installation and the ability to mutate or delete local records; without independent verification of the package/plugin publisher, this is better classified as suspicious than fully benign.
Confidence: 80%Severity: 54%
Audit Metadata