security-incident-response
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core incident-response content is benign documentation, but the skill embeds a transitive skill-install prompt and local skill-directory inspection that are not necessary for incident handling. Because the install path uses an official CLI but points to a third-party repo with unpinned installs, this is best classified as medium supply-chain risk rather than malware.
Confidence: 88%Severity: 62%
Audit Metadata