caveman-discover

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose mostly matches its behavior, but it extends third-party gateway usage into more code paths, inherits trust from another setup skill, and sits adjacent to API-key-bearing headers. No direct credential theft or hidden exfiltration is present, but transitive trust and ecosystem install/provenance ambiguity raise medium security concern.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Aug 11, 2026, 02:47 PM
Package URL
pkg:socket/skills-sh/juliusbrussee%2Fcaveman%2Fcaveman-discover%2F@0e764b1306235a4e33a39eb39fb03660badfbffaec7229fd745945f6f1c98271
Security Audit — socket — caveman-discover