weekly-report-repos
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent and it does not request disproportionate credentials or exfiltrate data, but it relies on executing a remotely fetched CLI from a personal GitHub repository via `uvx`. That unverifiable execution path makes the overall risk high despite otherwise narrow functionality.
Confidence: 84%Severity: 72%
Audit Metadata