skill-menu
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Suspicious rather than malicious. The skill’s purpose and behavior mostly align for local skill selection, but it depends on an unverifiable local binary and then activates other skill files, creating a real trust-chain risk even without credential access or network exfiltration.
Confidence: 85%Severity: 78%
Audit Metadata