input-validation-checker
Warn
Audited by Socket on May 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is a benign input-validation helper, but the broad Bash(npm:*) permission is disproportionate to the vague instructional scope and creates medium supply-chain risk. No concrete credential theft or exfiltration behavior is present, so this is not confirmed malware.
Confidence: 84%Severity: 56%
Audit Metadata