chadboyda-gtm
Warn
Audited by Socket on Jun 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the visible stub is not overtly malicious, but its primary behavior is to install a separate skill set from a personal GitHub repo through an unpinned CLI, creating transitive trust risk. The limited local footprint and official CLI path prevent a malicious classification, but the externalized behavior makes it higher risk than a self-contained documentation skill.
Confidence: 87%Severity: 62%
Audit Metadata