oracle

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior mostly fits its stated purpose, and install provenance is same-publisher and publicly verifiable, so this is not malware. However, it centralizes trust in an external CLI that receives API keys and selected repo files, can automate signed-in browser sessions, and supports remote-host/proxy-style routing; those are meaningful but proportionate medium risks for a code-review assistant skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 11, 2026, 06:38 AM
Package URL
pkg:socket/skills-sh/steipete%2Fagent-scripts%2Foracle%2F@9b142cf1dbef718de7b21ad9e070fe39c383034f