type-specimen
Warn
Audited by Socket on Aug 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS due to install-trust ambiguity rather than malicious behavior: the skill’s purpose, data flows, and permissions are mostly proportionate, and Google Fonts usage is official, but the core scripts/specimen executable is required and not verifiably sourced from the skill text. No credential harvesting or overt exfiltration is evident.
Confidence: 84%Severity: 72%
Audit Metadata