0day-scanner
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose and capabilities mostly align for a security-review tool, and there are no installers, credential-file reads, or obvious exfiltration endpoints. Risk comes from offensive security functionality plus unclear data routing: scanned code and findings may be sent to unspecified internal REST/MCP services and stored in an unspecified DB/graph, while the skill processes untrusted repo content in a tool-using workflow. This is not confirmed malware, but it is a medium-risk skill with unverifiable backend ownership and persistence behavior.
Confidence: 84%Severity: 56%
Audit Metadata