stinkyboy
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's hosted-MCP model broadly matches its stated purpose, but trust is concentrated in an opaque remote endpoint that can execute or synthesize arbitrary tools, and the claimed public docs/catalog were not verifiable. No direct malware or credential-stealing behavior is shown, but the black-box service design and weak verifiability make this a medium-risk integration.
Confidence: 82%Severity: 56%
Audit Metadata