rule-validate
Warn
Audited by Socket on Oct 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated validation purpose is coherent, but the skill introduces a disproportionate supply-chain risk by invoking an unpinned third-party npm tool (`@rayhanadev/truffler`) via `bunx` without same-org provenance or verification guidance. No clear credential harvesting or exfiltration is present, so this is better classified as a risky workflow dependency than malware.
Confidence: 86%Severity: 58%
Audit Metadata