denario

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: overall footprint mostly matches a legitimate research-automation skill, and the main install path is coherent with official PyPI/GitHub project docs. Risk is elevated by unpinned dependencies, weaker package provenance, optional Docker use with mounted `.env` credentials, and unspecified external-content/literature-search handling; these are meaningful security concerns but not evidence of confirmed malware.

Confidence: 83%Severity: 53%
Audit Metadata
Analyzed At
May 11, 2026, 02:49 PM
Package URL
pkg:socket/skills-sh/foryourhealth111-pixel%2FVibe-Skills%2Fdenario%2F@94ba47de6bacf9fcfb571216282bf655516ffab6