openapi-directory-first
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and capabilities mostly align, and its data flows go to legitimate GitHub/APIs.guru endpoints with no credential collection or exfiltration. The main concern is transitive installation of a personal third-party skill via unpinned npx-based tooling, plus reliance on external content for agent reasoning; this is medium risk but not malicious.
Confidence: 87%Severity: 56%
Audit Metadata