power-engineer
Warn
Audited by Socket on May 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the visible behavior is mostly consistent with a project-setup skill, but its defining capability is to install other skills and reconfigure agent behavior, while the actual installation provenance is not shown here. No direct credential theft, exfiltration endpoint, or confirmed malicious payload is visible in the snippet, so this is not confirmed malware; the main risk is transitive trust and unclear install execution details.
Confidence: 84%Severity: 66%
Audit Metadata