jentic-api-improve
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core function is coherent with its OpenAPI-improvement purpose, and its main external tools appear to be official Jentic or standard registry packages. However, it materially increases execution trust by encouraging bypassed permissions, wildcard Bash pre-approval, mutable `@latest` installs, Docker image pulls, and optional forwarding of spec context and credentials to external providers. This looks like a legitimate but high-trust automation skill rather than malware.
Confidence: 84%Severity: 66%
Audit Metadata