apm-usage
Warn
Audited by Socket on May 11, 2026
1 alert found:
AnomalyAnomalySKILL-ja.md
LOWAnomalyLOW
SKILL-ja.md
SUSPICIOUS: the skill is internally consistent as an APM usage guide, but its main purpose is to install and activate other skills, which creates a significant transitive trust and supply-chain risk. No clear exfiltration or deceptive routing is shown, so this is not confirmed malware; risk comes from arbitrary skill installation, hook execution, and credential-assisted private repo access.
Confidence: 88%Severity: 64%
Audit Metadata