conductor
Warn
Audited by Socket on May 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches its behavior, and no external exfiltration path is visible, but it depends on unverifiable local scripts and enables cross-session visibility plus queued instruction injection into other Claude sessions. Risk is moderate and primarily local-trust/lateral-control rather than confirmed malware.
Confidence: 87%Severity: 56%
Audit Metadata