shortcut
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose mostly matches its Shortcut-management actions, but trust is weakened by dependence on a community CLI, a mismatched npm install instruction, and credential forwarding through third-party client code. There is no clear evidence of malware or off-platform exfiltration, but the install/auth chain is not fully consistent with official Shortcut tooling.
Confidence: 84%Severity: 64%
Audit Metadata