learn
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core /learn functions are benign and mostly local, but this skill's actual footprint is much broader than its stated purpose. The shared gstack preamble adds telemetry, artifact sync, network/git activity, file mutations, and even repo-changing workflows that do not belong in a learnings manager. This looks more like an over-privileged framework wrapper than targeted malware, but the scope and opaque helper binaries make the skill higher risk than its description suggests.
Confidence: 81%Severity: 68%
Audit Metadata