consume-feed
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The documented purpose and visible commands are coherent for RSS ingestion, and no obvious credential harvesting or third-party proxying is shown. But the skill’s entire operational path relies on an undisclosed executable `./run.sh`, making install/execution trust unverifiable and raising overall risk until that script and its data flows are reviewed.
Confidence: 76%Severity: 72%
Audit Metadata