bridge-plugin

Warn

Audited by Socket on May 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core behavior is mostly aligned with its stated purpose as a local plugin bridge, and no credential theft or exfiltration is evident. The main concern is install trust: it recommends transitive installation from a personal GitHub repo via the official Skills CLI, plus a questionable `pip:yaml` dependency name, which makes the supply chain less verifiable than expected.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 24, 2026, 08:28 AM
Package URL
pkg:socket/skills-sh/richfrem%2FProject_Sanctuary%2Fbridge-plugin%2F@2df9fbc879f1db2add3fbdd69862459a4fec8b01
Security Audit — socket — bridge-plugin