mycelium
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the intended capability—managing repository memory via git notes—is coherent and proportionate, and no credential theft or off-platform API routing is shown. However, the skill’s core functionality depends on an unverifiable local CLI (`mycelium.sh`) with no documented publisher, source, or release trail, so the install/execution trust is materially weak and drives the risk high.
Confidence: 89%Severity: 78%
Audit Metadata