sage

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities generally align, but it forces use of external MCP services—especially a third-party researcher stack—instead of native tools, creating unnecessary trust and prompt-injection exposure. No clear credential theft or malicious exfiltration is shown, but the external-content processing and third-party tool dependency make the skill medium-to-high risk.

Confidence: 83%Severity: 67%
Audit Metadata
Analyzed At
Aug 31, 2026, 06:47 PM
Package URL
pkg:socket/skills-sh/jimweller%2Fclanker-skills%2Fsage%2F@c54f4985ad6041a463dd6d69eeb75f535b104fb6600e01f70c96cfc7f576a354
Security Audit — socket — sage