enterprise-user-management-system-ai
Warn
Audited by Socket on Oct 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities and data flows fit its stated purpose, and the examples mostly show normal local full-stack development patterns. The main issue is install trust: the skill is published under ara.so/reason-machines branding but instructs cloning a personal GitHub repo with unpinned npm/pip dependency installation and no integrity verification, creating a moderate supply-chain risk. No evidence of overt malware, credential harvesting, hidden exfiltration, or malicious pre-execution behavior is present in the provided content.
Confidence: 91%Severity: 58%
Audit Metadata