narrative-landscape
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s marketing purpose mostly aligns with its data access, but it requires running an unverified local executable and processes open-ended external content without clear trust boundaries. I found no direct credential harvesting or explicit exfiltration, so this is higher security risk than confirmed malware.
Confidence: 82%Severity: 74%
Audit Metadata