mushi-debug
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly aligned with a Mushi debugging purpose, but it routes raw provider API keys through a third-party CLI and assumes broad access to production observability and database tooling. No direct malware or obvious exfiltration path is shown, yet the credential-forwarding and operational scope make it a meaningful security risk.
Confidence: 80%Severity: 62%
Audit Metadata