expanso-remove-pii
Warn
Audited by Socket on Jun 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The purpose is plausible, but the install path and binary naming are inconsistent with official Expanso documentation, and the skill references unspecified credentials plus unseen scripts/pipeline that could route sensitive data elsewhere. No confirmed malicious behavior is visible in the provided text, but the trust and data-flow gaps make the skill medium risk.
Confidence: 100%Severity: 60%
Audit Metadata