trace
Warn
Audited by Socket on Jul 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The discovery purpose generally matches the search capabilities, but the footprint is broader than necessary: it mines local session history, scans cross-repo directories, clones arbitrary URLs, and forwards results to custom Oracle tooling. The key risk is reliance on an unverifiable local dig script plus custom Oracle data flows, which makes the skill high risk even without clear malicious intent.
Confidence: 83%Severity: 78%
Audit Metadata