running-with-without-evals
Warn
Audited by Socket on Jun 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the skill materially relies on executing plugin code inside OpenCode while preserving local authentication state. There is no clear malicious behavior or off-platform credential routing in the text, yet the plugin/runtime trust boundary and transcript-generation workflow create meaningful security risk beyond a purely documentation-only skill.
Confidence: 100%Severity: 60%
Audit Metadata