agent-messenger
Warn
Audited by Socket on Apr 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s messaging capabilities are broadly consistent with its stated purpose, but the install/provenance story is not. The claimed npm package, web domain, and verified open-source project do not line up cleanly, creating a meaningful supply-chain trust issue; combined with non-interactive messaging actions, this makes the skill medium/high risk rather than benign.
Confidence: 82%Severity: 74%
Audit Metadata