offload-r2
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely coherent with its stated purpose and uses plausible same-project endpoints, but it explicitly reads raw AWS-style credentials from a hardcoded local `.env` and performs external uploads plus repo rewrites. This looks like a specialized internal workflow rather than obvious malware, yet the credential-file access and outbound transfer path make it medium risk.
Confidence: 84%Severity: 57%
Audit Metadata