mlx-brain
Warn
Audited by Socket on May 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose broadly matches local/remote MLX inference, but its footprint includes remote command execution and an unversioned local workspace script with weak install provenance. No clear credential harvesting or exfiltration is shown, so this is not malicious, but it carries medium risk due to command execution trust and opaque local dependencies.
Confidence: 100%Severity: 60%
Audit Metadata