benchmark-models
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the skill’s real execution path is too opaque: a local Bash script and composed skills do the core work, and model traffic is routed through an unspecified /scillm component rather than a clearly documented official API. No direct credential theft or exfiltration is shown in the provided text, but install trust and data-flow integrity are insufficiently verifiable.
Confidence: 81%Severity: 58%
Audit Metadata