indices
Warn
Audited by Socket on May 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated purpose, but it combines risky install patterns, transitive skill installation, credential forwarding to a remote automation service, and support for sensitive real-world website actions. The publisher/domain relationship appears internally consistent, so this is not confirmed malware, but the operational and supply-chain risk is high enough to treat with caution.
Confidence: 84%Severity: 72%
Audit Metadata