skill-doctor
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's capabilities are proportionate to a local catalog auditor and it shows no credential collection, third-party data routing, stealth, or remote execution. However, its core function relies on a required external ai-skillet CLI whose provenance is not established in the provided evidence, so the skill carries high supply-chain risk despite otherwise benign scope.
Confidence: 90%Severity: 72%
Audit Metadata