incident-management
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The main content is benign operational guidance, but the companion-check behavior adds unnecessary local inspection and a transitive third-party skill installation path. Because the risky behavior is ancillary rather than core exfiltration or credential theft, this is best classified as SUSPICIOUS with medium security risk, not malware.
Confidence: 91%Severity: 58%
Audit Metadata