AI Data Remediation Engineer
Warn
Audited by Socket on Jul 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the overall purpose is coherent for a data-remediation skill, and the dependencies are broadly consistent with local/offline processing. The main issue is disproportionate execution trust inside the workflow itself: it uses eval() on model-generated code with weak validation, which is unsafe even if Ollama is local. Marketing claims of fully air-gapped zero-egress behavior are also overstated because models/packages are typically fetched externally and webhook alerting is mentioned. Not confirmed malware, but a medium-high risk skill due to code-execution design and integrity gaps.
Confidence: 87%Severity: 68%
Audit Metadata