knowcards
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent for a repo-memory helper, but the skill forces execution of an unverifiable, unpinned external npm CLI before normal work. No credential harvesting or overt exfiltration is shown, yet install/execution trust is disproportionally weak for a mandatory workflow dependency.
Confidence: 87%Severity: 72%
Audit Metadata