enterprise-user-management-ai-analytics

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The documented app behavior is broadly consistent with enterprise user management and ML analytics, and there is no direct credential theft or covert exfiltration. The main risk is install trust: the skill published under different branding instructs execution of substantial third-party code from an unrelated personal GitHub repo with unpinned npm/pip dependencies, making the supply chain footprint higher than expected for a skill guide.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Oct 1, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fdata-skills%2Fenterprise-user-management-ai-analytics%2F@040725fc0283a9f0b36b38966e61ee8ea79637fed9ad637622f5e35d8ef02763
Security Audit — socket — enterprise-user-management-ai-analytics