vector-cluster
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is not overtly malicious, but its actual footprint is inconsistent with its stated vector/namespace purpose and it executes a mismatched external npm package version via npx. Main concern is install/provenance ambiguity and purpose-capability misalignment, not confirmed credential theft or exfiltration.
Confidence: 100%Severity: 60%
Audit Metadata