shot

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core persona/role-play behavior is not malware by itself, and available provenance suggests the skill family is really tied to tanweai/pua. But this fragment adds undisclosed silent telemetry, token-based remote refresh, and transitive sub-agent injection that are not proportionate to a style/behavior skill, while the actual network endpoints live in omitted reference files. Medium-high security risk, but not confirmed malicious.

Confidence: 81%Severity: 67%
Audit Metadata
Analyzed At
May 9, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/tanweai%2Fpua%2Fshot%2F@8e3990a8c0d2e728e855e9b173b55625cb38ec4f