pitch

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated behavior is benign and narrowly scoped, but its core functionality depends on an unverifiable local distill executable with no official install or release provenance established. No malicious data flow is shown, yet the dependency trust gap alone makes this a high security-risk skill.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
May 7, 2026, 03:14 PM
Package URL
pkg:socket/skills-sh/jazz1x%2Fgalmuri%2Fpitch%2F@b177f09f4d2243f868b08b1f668a3a301430128b