soia-pkm-interpret
Warn
Audited by Socket on Jul 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the runtime behavior is mostly coherent and local-only, but the documented install path is broader than necessary because it installs a third-party skill with wildcard agent permissions. No clear credential theft or exfiltration is present, so this is not malware, but the transitive install trust and overbroad permission scope raise medium security risk.
Confidence: 80%Severity: 56%
Audit Metadata