mycelium

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the intended capability—managing repository memory via git notes—is coherent and proportionate, and no credential theft or off-platform API routing is shown. However, the skill’s core functionality depends on an unverifiable local CLI (`mycelium.sh`) with no documented publisher, source, or release trail, so the install/execution trust is materially weak and drives the risk high.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Mar 29, 2026, 11:47 PM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Fmycelium%2F@d008eec633d1186516b415c9f78896b870b08789