music-connect
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's overall purpose is coherent, but it asks the agent to download and execute an npm package at runtime and hand it a live Cognitum PAT. The main concerns are mutable `@latest` installation, incomplete publisher/provenance verification for `cogmusic`, and credential forwarding to third-party code; absent stronger evidence that the package is officially owned by Cognitum, this is higher-risk than a normal documentation/setup skill.
Confidence: 83%Severity: 72%
Audit Metadata