revor-company-discovery
Warn
Audited by Socket on Sep 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's core capability aligns with company discovery and its main network destination is the official Revor service, but the fallback path weakens trust by using an unverifiable local script and, more importantly, instructing users to send API keys in chat and save them in a shared local .env file. This is a credential-handling mismatch with Revor's own documented secret-based setup, so the skill is not malicious on its face but carries medium security risk.
Confidence: 86%Severity: 61%
Audit Metadata