analysis-core
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the methodology itself is coherent and mostly well-scoped, but it includes a transitive skill-install path to a third-party repo and uses a wildcard install that expands trust to all skills in that repository. No direct credential theft or exfiltration is evident, so this is better classified as medium/high security risk from transitive trust and supply-chain exposure rather than malware.
Confidence: 89%Severity: 68%
Audit Metadata