lexi

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose and local file flows are mostly coherent for a lexicon-analysis skill, and there is no explicit credential collection or network routing. However, it requires execution of an unverifiable bundled `honne` script with unclear provenance, so install/execution trust is not established and overall risk remains high despite limited visible data exfiltration.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Apr 29, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/jazz1x%2Fhonne%2Flexi%2F@afd1d9299d2d84089ba6b19d265e57069254ef0a