using-khuym

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's orchestration behavior mostly matches its stated bootstrap purpose, and its repo writes are disclosed and user-gated. The main concern is install/execution trust: it depends on several external tools, with br and cm not clearly verifiable from the provided evidence, which triggers a high supply-chain risk floor even without direct evidence of malicious intent or credential theft.

Confidence: 79%Severity: 74%
Audit Metadata
Analyzed At
Apr 14, 2026, 02:27 PM
Package URL
pkg:socket/skills-sh/hoangnb24%2Fskills%2Fusing-khuym%2F@a9a59c21213f7f346a8a8df5a0a8b84c97783f3c