inno-idea-eval
Warn
Audited by Socket on Sep 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's core behavior fits its stated purpose, but it relies on an unverifiable transitive dependency in ~/.claude/skills/searching-ai-papers and ingests untrusted external content into a write-capable evaluation pipeline. No credential harvesting, exfiltration endpoint, or covert real-world action is evident, so this is better classified as a high-risk workflow dependency/prompt-surface issue than malware.
Confidence: 84%Severity: 72%
Audit Metadata