fix
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose is coherent, and the install sources are largely official and same-org, so there is no strong evidence of malware or credential theft. However, it dynamically installs other skills, uses an unpinned `@latest` CLI, and delegates code, publishing, and deployment actions to child skills, creating a meaningful transitive trust and autonomy risk.
Confidence: 87%Severity: 58%
Audit Metadata