meta-theory
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core governance behavior is mostly coherent with the stated purpose, but the skill's footprint expands significantly through transitive skill/plugin installation and opaque bootstrap commands. There is no direct malware or credential-harvesting evidence here, yet the dependency and trust chain risk is high enough to treat this skill as medium-high security risk.
Confidence: 89%Severity: 74%
Audit Metadata