product-validation
Warn
Audited by Socket on Sep 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Mostly coherent and purpose-aligned product validation skill with restrained scope and explicit safety boundaries. Main risk is the optional `manuvra` CLI: it is referenced as executable tooling but its provenance is not established, making this a suspicious supply-chain dependency rather than clear malware. No credential harvesting, stealth, proxy routing, or exfiltration behavior is evident in the skill text.
Confidence: 89%Severity: 72%
Audit Metadata