using-khuym
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's orchestration behavior mostly matches its stated bootstrap purpose, and its repo writes are disclosed and user-gated. The main concern is install/execution trust: it depends on several external tools, with br and cm not clearly verifiable from the provided evidence, which triggers a high supply-chain risk floor even without direct evidence of malicious intent or credential theft.
Confidence: 79%Severity: 74%
Audit Metadata