metro-ai-apps-builder

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated orchestration purpose matches its behavior, but its core mechanism is high-risk transitive installation and delegation to external skills via a third-party CLI. No direct credential theft or covert exfiltration is present here, yet the runtime trust expansion and unverifiable downstream behavior make it a significant security risk.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Aug 21, 2026, 12:07 AM
Package URL
pkg:socket/skills-sh/open-edge-platform%2Fedge-ai-suites%2Fmetro-ai-apps-builder%2F@167c4f2f109e847a9e090230a980055ef658229c45feb72857ff7446c2e4c8e3
Security Audit — socket — metro-ai-apps-builder