client-health-dashboard

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose mostly aligns with its data-access capabilities, but it requests a very broad cross-system footprint, including private Slack and Gmail content, and uses unverifiable MCP connectors whose backend data flows are not shown. No malware indicators, remote installers, or explicit credential theft appear, but the scope and opaque connector trust make this higher-risk than a narrowly scoped reporting skill.

Confidence: 84%Severity: 61%
AnomalyLOW
references/data-sources.md

This is a broad client-data aggregation specification, not executable malware. It presents a significant privacy and least-privilege risk if run without explicit authorization, scoped queries, sensitive-data redaction, and controlled storage, particularly because it requests private Slack, Gmail, CRM, billing, and local-file data. No direct malicious behavior is demonstrated in the supplied text.

Confidence: 98%Severity: 63%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:01 PM
Package URL
pkg:socket/skills-sh/onewave-ai%2Fclaude-skills%2Fclient-health-dashboard%2F@7f8de790833701a5b53e5884f10a8e1f7091d471572d27bb02fd7a3a574921bd
Security Audit — socket — client-health-dashboard