context-hub
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent with the capability: fetching API docs before coding. However, the skill relies on an undocumented preinstalled CLI of unclear provenance and routes documentation through that intermediary rather than official vendor docs. There is no explicit credential access, file harvesting, or obvious exfiltration behavior in the skill text, so this is not confirmed malware, but the unverifiable external CLI and indirect data path create meaningful supply-chain and content-integrity risk.
Confidence: 84%Severity: 72%
Audit Metadata