toolkit-scout

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose as a toolkit index is mostly consistent with its content, but it expands trust to many external and local executables. The main risk is transitive: it instructs the agent to run unverifiable local scripts and route into other powerful workflows, including deployment, account-cookie refresh, outreach automation, and LinkedIn actions via Unipile. This is not confirmed malware, but it is a medium/high-risk coordination skill because its effective footprint is much broader than a passive reference document.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Jul 15, 2026, 12:56 PM
Package URL
pkg:socket/skills-sh/Lua2147%2Fclaude-toolkit-catalog%2Ftoolkit-scout%2F@209231c84b1285a205ff580a91aa69da5f830289368712a8d36965ee1d5a1e13
Security Audit — socket — toolkit-scout