writing-core
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s writing-focused behavior is otherwise coherent and low risk, but it instructs installation of additional skills from a personal GitHub repo via a mutable GitHub-backed CLI path. That transitive trust and supply-chain exposure make it riskier than a pure documentation skill, though there is no evidence of credential theft, exfiltration, or overtly malicious behavior in this skill itself.
Confidence: 89%Severity: 52%
Audit Metadata