tuckmark-agent-import-user
Warn
Audited by Socket on Aug 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow is broadly consistent with an inventory-import skill and includes privacy-preserving instructions, but it requires an unverifiable external CLI with unclear provenance and credential handling. That makes the main risk supply-chain trust rather than confirmed malicious behavior.
Confidence: 84%Severity: 72%
Audit Metadata