meta-onboarding
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly aligned with legitimate Meta API onboarding and uses official Meta/Anthropic/PyPI sources, but it unnecessarily asks the user to disclose sensitive Meta secrets to the agent and then stores them locally. No clear malicious exfiltration is shown, yet the secret-handling pattern and execution of an unseen local script make this higher than benign.
Confidence: 84%Severity: 56%
Audit Metadata