enrich
Warn
Audited by Socket on Aug 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core capability matches the stated purpose of knowledge-base enrichment, and there is no malicious installer or obvious credential theft path. However, the skill encourages sending existing internal knowledge to external research services and processing untrusted external content while retaining write access, creating meaningful privacy and prompt-injection risk. Documentation is also internally inconsistent about required tools.
Confidence: 87%Severity: 61%
Audit Metadata