metro-ai-apps-builder
Warn
Audited by Socket on Aug 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated orchestration purpose matches its behavior, but its core mechanism is high-risk transitive installation and delegation to external skills via a third-party CLI. No direct credential theft or covert exfiltration is present here, yet the runtime trust expansion and unverifiable downstream behavior make it a significant security risk.
Confidence: 88%Severity: 76%
Audit Metadata