edge-hint-extractor

Warn

Audited by Socket on May 9, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
README.md

SUSPICIOUS: the core skill is coherent and mostly local, but the optional --llm-ideas-cmd mode expands the trust boundary to arbitrary external code without provenance or verification. Not malicious on its face, yet the external CLI hook creates medium security risk disproportionate to a simple hint-extraction workflow when safer file-based augmentation is already supported.

Confidence: 84%Severity: 56%
AnomalyLOW
SKILL.md

SUSPICIOUS: the core skill is coherent and mostly local, but the optional --llm-ideas-cmd mode expands the trust boundary to arbitrary external code without provenance or verification. Not malicious on its face, yet the external CLI hook creates medium security risk disproportionate to a simple hint-extraction workflow when safer file-based augmentation is already supported.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 9, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/mphinance%2Falpha-skills%2Fedge-hint-extractor%2F@e45bafa4ede4c1328287e9e16b250819b8109477
Security Audit — socket — edge-hint-extractor