ingest

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core behavior is mostly aligned with its stated ingestion purpose, but it persistently captures user and fetched content, uploads raw materials to external storage, and relies on a same-org but weakly verified external CLI/install chain. This looks more like a high-trust knowledge-ingestion skill than malware, but it carries meaningful privacy, supply-chain, and autonomous-write risk.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Aug 29, 2026, 06:20 PM
Package URL
pkg:socket/skills-sh/praxstack%2Fskills-and-personas%2Fingest%2F@68f1dca3cdc473b58bd3001a9bd6f8f24468bbd5b23f5fb3cb4f736d43dc0037
Security Audit — socket — ingest