cors-policy-validator
Warn
Audited by Socket on May 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is benign and narrowly scoped, but the actual permission footprint is broader than needed because Bash(npm:*) enables arbitrary package installation and code execution without any pinned dependency or documented necessity. No direct credential theft or exfiltration is present, so this is not malicious, but it is over-permissioned for its purpose.
Confidence: 89%Severity: 56%
Audit Metadata