openevidence-install-auth
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and credential scope are broadly consistent with setting up an API integration, and there is no exfiltration pattern or hidden execution. However, trust evidence is incomplete: the referenced official domain appears legitimate, but the exact SDK/package provenance was not independently confirmed from official docs, the dependency is unpinned, and the Python instructions are incomplete. That makes this more likely a shaky or unverifiable integration guide than a malicious credential harvester.
Confidence: 87%Severity: 58%
Audit Metadata