polish
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core polish instructions are benign and aligned with frontend QA, but the skill mandates transitive use of other skills, including a third-party community skill installed through an unpinned external flow. That added trust chain is disproportionate to a simple UI-polish task, raising medium security concern even without direct credential collection or explicit exfiltration.
Confidence: 85%Severity: 56%
Audit Metadata