to-issues
Warn
Audited by Socket on Aug 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core behavior fits the stated purpose and GitHub/local modes are mostly proportionate, but the Baidu iCafe path relies on an externally authenticated CLI whose public provenance is unclear. This is not confirmed malware and shows no covert exfiltration, but the unverifiable enterprise CLI and real-world ticket creation capability make the skill medium risk overall.
Confidence: 84%Severity: 58%
Audit Metadata