brainstorm-workflow

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the host’s stated purpose matches its behavior, and there is no direct credential harvesting or exfiltration. The main risk is transitive trust: it installs/loads external skills from GitHub via `npx skills add`, so safety depends on those downstream skills and the CLI.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Aug 13, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/fudesign2008%2Fopen-skills%2Fbrainstorm-workflow%2F@cb7c6d6feb9338b3d21d135240bf8d3971b576c9c0c1101667adbe10879a2dff
Security Audit — socket — brainstorm-workflow