lore

Warn

Audited by Socket on Apr 14, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
lore/SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated purpose, and governance guidance is coherent, but it requires a proprietary Lore CLI that appears only partially verifiable from the provided evidence and directly handles auth tokens/API keys. Under the mandatory overrides, an unverifiable required CLI receiving credentials makes this high security risk even without clear evidence of malicious intent.

Confidence: 82%Severity: 84%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities are broadly consistent with a Lore backend management tool, and its data flows appear aimed at Lore-owned services rather than unrelated third parties. However, it relies on a remote-script-installed external CLI whose provenance is not independently verifiable from the evidence provided, and that CLI accepts API keys. This makes the skill high risk on install/execution trust and credential forwarding grounds, despite otherwise coherent purpose alignment.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Apr 14, 2026, 10:18 AM
Package URL
pkg:socket/skills-sh/pengelbrecht%2Fskills%2Flore%2F@862519d89c584722138ea1e760945da92037593b