mochi-srs

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose and workflow are coherent for a Mochi flashcard assistant, and its credential/file scope is mostly proportionate. However, it depends on a bundled local CLI in the skill directory and forwards a Mochi API key to it without enough provenance in the provided material; that makes this suspicious from a supply-chain and credential-handling perspective rather than clearly malicious.

Confidence: 81%Severity: 82%
Audit Metadata
Analyzed At
Jun 3, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/HartreeWorks%2Fskill--mochi-srs%2Fmochi-srs%2F@4ca4017c4504e5a918f9c927b5a56e33faa122ef
Security Audit — socket — mochi-srs