mochi-srs
Warn
Audited by Socket on Jun 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s stated purpose and workflow are coherent for a Mochi flashcard assistant, and its credential/file scope is mostly proportionate. However, it depends on a bundled local CLI in the skill directory and forwards a Mochi API key to it without enough provenance in the provided material; that makes this suspicious from a supply-chain and credential-handling perspective rather than clearly malicious.
Confidence: 81%Severity: 82%
Audit Metadata