Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is coherent and read-only, but the real data path is not. The main issue is proxy-mediated credential and request routing through sc-proxy instead of direct documented API access, plus inconsistent credential documentation. No strong malware indicators or malicious payload delivery are present, but the hidden intermediary makes the skill medium risk.
Confidence: 86%Severity: 58%
Audit Metadata