kaggle

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with a Kaggle integration and routes data to official Kaggle endpoints, but it has a broad action surface with real account side effects, untrusted-content processing plus Bash capability, and optional third-party skill-install channels that expand trust beyond Kaggle or the repo itself. No strong evidence of credential theft or covert exfiltration was shown.

Confidence: 86%Severity: 63%
Audit Metadata
Analyzed At
May 7, 2026, 07:32 AM
Package URL
pkg:socket/skills-sh/shepsci%2Fkaggle-skill%2Fkaggle%2F@f5d9bb09215769e806c4a53df03cc46231f93a2f