pii-detect
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's stated purpose is coherent, but its footprint routes highly sensitive input to third-party claude-flow MCP tools with limited transparency about endpoint handling, and it grants unnecessary Bash access. No direct malware behavior, credential theft, or covert execution is shown, but external processing of PII makes this a medium-risk skill.
Confidence: 100%Severity: 60%
Audit Metadata