narrative-lion
Warn
Audited by Socket on May 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities broadly match its stated Narrative Lion workflow, and network traffic goes to the official service domain rather than an obvious exfiltration proxy. However, the core executable is an unreviewed bundled local script with unclear provenance, and the skill forwards bearer credentials and user content through that script while enabling external writes/uploads. This is a coherent service integration, but the trust model is weaker than a normal official, verifiable CLI and therefore carries moderate risk.
Confidence: 85%Severity: 61%
Audit Metadata