phase-4-api
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: mostly coherent API-development guidance, but it expands into a third-party remote MCP/BaaS integration that can receive project data and credentials. No confirmed malware or covert exfiltration is evident, yet the external trust chain and credential forwarding to bkend create medium security risk.
Confidence: 80%Severity: 52%
Audit Metadata