recallmax
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Suspicious rather than malicious. The main risk is transitive installation of a third-party AI skill through an official CLI, with no visible implementation to verify whether the memory, summarization, and fact-checking claims are accurate or safely scoped. No direct credential theft or overt exfiltration is evident from the provided content alone, but the trust chain and untrusted-content ingestion make it medium risk.
Confidence: 84%Severity: 56%
Audit Metadata