resolve-recipe-ingredient-link
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose and local file access are mostly coherent, and there is no clear credential harvesting or exfiltration path. However, it requires an unverifiable local CLI binary with unknown provenance, which makes execution trust disproportionately risky for an otherwise benign vault-maintenance task.
Confidence: 84%Severity: 78%
Audit Metadata