spine-matrix
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated Matrix read/write purpose is coherent and the OAuth/device-flow guidance matches normal Matrix auth, with no clear third-party exfiltration path in the text. However, the skill's main functionality depends on a local `matrix` CLI/script whose provenance is not verifiable here, and that binary handles access/refresh tokens and room data; by policy this creates high supply-chain risk even though the visible instructions are otherwise proportionate.
Confidence: 88%Severity: 82%
Audit Metadata