learnings

Warn

Audited by Socket on Jul 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent and the visible data flows are mostly local, but the skill’s core behavior depends on an unverifiable local executable script with no provenance or release trail. That makes the main risk supply-chain and execution trust rather than confirmed maliciousness.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Jul 19, 2026, 05:20 PM
Package URL
pkg:socket/skills-sh/qwwiwi%2Fagentos-skills-public%2Flearnings%2F@6b5dd7b377eaa2e3048ca0feceacb4340bc91bcf183206ab3fe78bed4cfcd289
Security Audit — socket — learnings