aris-rebuttal
Warn
Audited by Socket on May 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core workflow is coherent for rebuttal drafting and there is no clear malware or credential-harvesting path, but the footprint is broader than necessary: wildcard Bash access, transitive skill invocation, and untrusted external review text processed alongside write/exec capabilities raise medium risk. Data sent to Codex MCP appears purpose-consistent rather than deceptive, so this is better classified as a vulnerable/overprivileged skill than malicious.
Confidence: 86%Severity: 58%
Audit Metadata