ai-matching-records

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The record-matching capability is coherent with the stated purpose, and the examples are mostly benign documentation. The main concern is the explicit instruction to install additional third-party skills through the skills CLI, which expands trust beyond this skill and introduces supply-chain risk; LLM data sharing and auto-merge behavior are proportional but still moderately risky for sensitive datasets.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 13, 2026, 06:47 PM
Package URL
pkg:socket/skills-sh/lebsral%2Fdspy-programming-not-prompting-lms-skills%2Fai-matching-records%2F@66777e37f13f0bc246dedfb572ec9cf6d0380536