faion
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s general purpose is plausible, but it uses pre-execution shell execution at load time, broad Python shell permissions, and an unverified local helper script that reads session context and repository files. There is no clear evidence of credential theft or external exfiltration, so this is not confirmed malware, but the execution model and scope are riskier than a normal documentation/retrieval skill.
Confidence: 100%Severity: 60%
Audit Metadata