cti-domain-research
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is mostly aligned with its stated CTI research purpose, but it carries medium risk because it combines untrusted web research with Bash access and optionally forwards data into a separate unreviewed NotebookLM connector plugin. Nothing here confirms malware, but the transitive plugin trust and prompt-injection exposure make it suspicious rather than fully benign.
Confidence: 79%Severity: 58%
Audit Metadata