investigate-alert

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s purpose is coherent for alert investigation, but its trust model is not. It relies on an unverifiable authenticated CLI (`gcx`) and a transitive prerequisite skill (`setup-gcx`), which materially raises supply-chain and credential-forwarding risk despite otherwise legitimate observability workflows.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Apr 7, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/grafana%2Fgcx%2Finvestigate-alert%2F@9434bdb4108c815042b2405e8e6b55772d402173
Security Audit — socket — investigate-alert