spark-cli-knowledge-sharing
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches a knowledge-sharing tool, but the skill’s footprint is broad: it requires an external authenticated CLI, mandates routine network use before coding, and encourages uploading project-derived insights to a third-party knowledge base. The main concern is not overt malware but disproportionate data-sharing and credential-forwarding through an insufficiently verified binary/service boundary.
Confidence: 85%Severity: 82%
Audit Metadata