paniolo-qmd
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities mostly align, with no credential harvesting, proxy API routing, or stealth behavior. The main issue is supply-chain trust: it installs and runs a platform-specific native binary with only weakly verifiable public provenance and no stated checksum/signature verification, which makes the skill high risk despite otherwise benign local-search behavior.
Confidence: 87%Severity: 72%
Audit Metadata