larrybrain

Warn

Audited by Socket on Jul 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose matches its behavior, but that purpose is inherently high-risk because it installs and activates remote third-party skills. Official LarryBrain API usage is internally consistent, yet the transitive trust chain, remote instruction-following, and mutable distribution evidence make this a risky marketplace/bootstrapper rather than a benign low-risk guide.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Jul 11, 2026, 07:22 AM
Package URL
pkg:socket/skills-sh/OllieWazza%2FLarryBrain-Skill%2Flarrybrain%2F@3fa1116c4034c29525df7c9ed8616669933a4bb0027d9c205493c9f5aa1b362d
Security Audit — socket — larrybrain