customer-persona
Warn
Audited by Socket on May 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core persona-research behavior is coherent, but the skill requires transitive installation of another skill plus an external CLI/service stack, which meaningfully increases trust and credential-handling risk relative to its simple stated purpose. Data flows appear aligned with research and avatar generation rather than overt theft, so this is not confirmed malware.
Confidence: 85%Severity: 58%
Audit Metadata