kelly-picks
Warn
Audited by Socket on Aug 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Overall this skill is mostly aligned with its stated product-research purpose and does not show clear credential theft or malicious exfiltration. The main risks are transitive trust in other skills and prompt-injection exposure from sweeping untrusted external content while retaining write capabilities, so the skill is better classified as suspicious/medium-risk rather than benign.
Confidence: 85%Severity: 58%
Audit Metadata