denario

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capabilities mostly fit a research-automation skill, and installs use normal PyPI tooling, but provenance is not fully coherent because the skill is published as K-Dense Inc. while the package/source trail points to AstroPilot-AI. No direct credential theft or overtly malicious data exfiltration is shown, yet the combination of third-party package trust, API-key forwarding, and broad multiagent automation makes this a medium-risk skill that warrants caution.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Mar 31, 2026, 08:25 AM
Package URL
pkg:socket/skills-sh/LeonChaoX%2Fqinyan-academic-skills%2Fdenario%2F@14ed518b42df4337b36b373b06d68c98336982ba
Security Audit — socket — denario