edge-hint-extractor
Audited by Socket on May 9, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the core skill is coherent and mostly local, but the optional --llm-ideas-cmd mode expands the trust boundary to arbitrary external code without provenance or verification. Not malicious on its face, yet the external CLI hook creates medium security risk disproportionate to a simple hint-extraction workflow when safer file-based augmentation is already supported.
SUSPICIOUS: the core skill is coherent and mostly local, but the optional --llm-ideas-cmd mode expands the trust boundary to arbitrary external code without provenance or verification. Not malicious on its face, yet the external CLI hook creates medium security risk disproportionate to a simple hint-extraction workflow when safer file-based augmentation is already supported.