happy-platform-skills
Audited by Socket on Aug 5, 2026
4 alerts found:
Anomalyx4SUSPICIOUS. The skill is purpose-aligned and uses official ServiceNow-style APIs, with no external installer or obvious exfiltration path. Risk is driven by broad ServiceNow privileges and arbitrary Background Script execution, which are powerful but plausibly related to the stated GRC analysis task.
SUSPICIOUS: The skill’s purpose and ServiceNow data access are coherent for GRC validation, and there is no direct exfiltration or malware behavior in the skill text. Risk comes from reliance on powerful background-script execution and unverified third-party MCP tooling that may receive ServiceNow credentials and data, making this medium-risk rather than benign.
SUSPICIOUS. The core data access aligns with contract metadata extraction and the documented network targets are official ServiceNow APIs, but the skill grants broader-than-necessary powers through custom/unverified MCP wrappers, background-script execution, and unused Bash capability. This looks more like an overprivileged enterprise automation skill than malware.
SUSPICIOUS. The root skill is mostly coherent as a catalog/discovery entry and uses a same-org npm/GitHub distribution path, but it explicitly installs and loads a large transitive set of additional skills. That broad trust expansion is disproportionate for a simple catalog skill and should be treated as medium risk until the child skills are separately reviewed.