muse-runner
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly coherent with its stated purpose and uses an official npm-distributed CLI, but it forwards prompts/files through an external CLI to a third-party provider path and may mutate persisted auth settings. Risk is medium due to external execution trust, provider credential reliance, and explicit outbound data sharing rather than clear malicious intent.
Confidence: 85%Severity: 56%
Audit Metadata