puda-workflows
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly aligned with its stated purpose, but it enables real-world robotic actions, requires a third-party OpenRouter API key, and delegates to another skill (puda-memory). No obvious malware or credential harvesting pattern is present, but the physical-action scope and transitive trust make it medium risk.
Confidence: 84%Severity: 58%
Audit Metadata