mushi-debug

Warn

Audited by Socket on Aug 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly aligned with a Mushi debugging purpose, but it routes raw provider API keys through a third-party CLI and assumes broad access to production observability and database tooling. No direct malware or obvious exfiltration path is shown, yet the credential-forwarding and operational scope make it a meaningful security risk.

Confidence: 80%Severity: 62%
Audit Metadata
Analyzed At
Aug 7, 2026, 01:40 PM
Package URL
pkg:socket/skills-sh/kensaurus%2Fmushi-mushi%2Fmushi-debug%2F@3499973bd0e82ec3872ae467a23f762832e8edf0c48087a4d3468b574ef619a8
Security Audit — socket — mushi-debug