skillify
Warn
Audited by Socket on May 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the repo-scaffolding behavior is broadly consistent with a meta-skill, but the cross-modal eval design routes provider API keys and evaluated content through a third-party gbrain gateway instead of direct official APIs. Combined with broad exec/read/write access and external CLI dependence, this is a medium-high security risk even without evidence of confirmed malware.
Confidence: 86%Severity: 78%
Audit Metadata