personize-governance

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent with Personize governance management and official same-brand endpoints, but the skill’s scope is broader than its stated purpose and includes autonomous write paths, attachment/script retrieval, and transitive skill installation. This looks more like a powerful admin/automation skill than a narrowly scoped governance editor, creating medium security risk despite no clear evidence of credential theft or malicious exfiltration.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/personizeai%2Fpersonize-skills%2Fpersonize-governance%2F@133cf1180fd10afb08d4a0b03c311b73c2b38a44