design-review
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the catalog entry is not malicious on its face, but it mainly functions as a pointer that asks the user to install another upstream skill bundle and execute its setup. The main risk is transitive skill installation plus external setup execution; no direct credential harvesting or exfiltration is shown in this entry.
Confidence: 87%Severity: 74%
Audit Metadata