content

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: purpose is mostly coherent, but the skill uses load-time shell execution to read local files into prompt context, including accounts.md. There is no external install path, outbound network exfiltration, or credential forwarding, so this is not confirmed malware; the main issue is pre-execution trust and unnecessary local data exposure.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Aug 26, 2026, 09:35 PM
Package URL
pkg:socket/skills-sh/lilmgenius%2Fpolysona%2Fcontent%2F@63098f9088c89899008e5b5dc2a8c6738965aaeb1c3a2b20ca681d8c8ad063e1
Security Audit — socket — content