shot
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core persona/role-play behavior is not malware by itself, and available provenance suggests the skill family is really tied to tanweai/pua. But this fragment adds undisclosed silent telemetry, token-based remote refresh, and transitive sub-agent injection that are not proportionate to a style/behavior skill, while the actual network endpoints live in omitted reference files. Medium-high security risk, but not confirmed malicious.
Confidence: 81%Severity: 67%
Audit Metadata