mock-ollama

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s proxy/monitoring behavior is consistent with its stated purpose, but it requires routing all LLM traffic and upstream API keys through a globally installed third-party CLI, with unpinned npm install and only partial publisher verification. This is not confirmed malware, but it is a medium-high security risk due to credential forwarding and full visibility into prompt/response data.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Aug 7, 2026, 03:14 PM
Package URL
pkg:socket/skills-sh/gitByEOS%2Fopen-part-skills%2Fmock-ollama%2F@d668364fad84e5a009fab332dd7ae22c8bf1b5b7cb25e34c9b752417c1365762
Security Audit — socket — mock-ollama