review-forecast

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the visible skill is mostly a benign, read-only sales forecast workflow and its data access is proportionate to purpose, but it requires execution of an unseen helper skill preflight script. With no public provenance or code for that transitive dependency, trust and data-flow verification are incomplete, raising moderate security concern rather than indicating confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/openai%2Frole-specific-plugins%2Freview-forecast%2F@60d505ce8c562ded84a0e8a50fac731d8ea04a8399bb5b74cd12568f690ead8b
Security Audit — socket — review-forecast