analyze-experiment
Warn
Audited by Socket on Jul 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and requested data access fit experiment analysis, but its trust model depends on an unverifiable externally installed `tpc` CLI obtained through a raw `curl|bash` installer. Because that CLI is authenticated and handles sensitive run/transcript data, the install and credential-forwarding risk is high even without direct evidence of malicious exfiltration.
Confidence: 86%Severity: 84%
Audit Metadata