ai-detecting-anomalies

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core anomaly-detection guidance is coherent and the DSPy/LM data flow matches the stated purpose, but the skill weakens trust by instructing installation from a personal GitHub repo via unpinned `npx skills add` and by recommending an additional transitive skill install from the same source. This is more a supply-chain and trust-boundary concern than confirmed malware.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
May 13, 2026, 06:47 PM
Package URL
pkg:socket/skills-sh/lebsral%2Fdspy-programming-not-prompting-lms-skills%2Fai-detecting-anomalies%2F@c081c4439134c43a0b1035d19719e148a4c3c8b8
Security Audit — socket — ai-detecting-anomalies