pro
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core local-state features are mostly aligned with the stated purpose, but the skill contains a material contradiction: it claims all telemetry/networking was removed while still instructing silent remote config refresh and session_start reporting. With no endpoint or executable payload shown, this is not confirmed malware, but the hidden/background behavior and unresolved data-flow inconsistency make it higher risk than a benign local-only skill.
Confidence: 84%Severity: 57%
Audit Metadata