client-health-dashboard
Audited by Socket on Sep 15, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: The skill's purpose mostly aligns with its data-access capabilities, but it requests a very broad cross-system footprint, including private Slack and Gmail content, and uses unverifiable MCP connectors whose backend data flows are not shown. No malware indicators, remote installers, or explicit credential theft appear, but the scope and opaque connector trust make this higher-risk than a narrowly scoped reporting skill.
This is a broad client-data aggregation specification, not executable malware. It presents a significant privacy and least-privilege risk if run without explicit authorization, scoped queries, sensitive-data redaction, and controlled storage, particularly because it requests private Slack, Gmail, CRM, billing, and local-file data. No direct malicious behavior is demonstrated in the supplied text.