agency-evidence-collector
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated QA purpose mostly matches the visible capabilities, and there is no explicit external credential routing or obvious exfiltration path in the text. However, the skill instructs execution of an unprovided local script, making a core part of its behavior unverifiable; under the skill-specific scoring rules, that raises supply-chain risk materially even though the apparent intent is benign QA automation.
Confidence: 84%Severity: 72%
Audit Metadata