acpx-faq

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Most of the skill is a legitimate operational guide for acpx, and the codex/claude adapter flows align with the stated purpose. The main issue is the agy workflow: it requires a custom local `.par` executable whose provenance is not verified in the provided evidence, yet it participates in authentication and agent execution. That makes the skill's overall footprint higher risk than a normal documentation skill, even though there is no confirmed malicious payload or explicit exfiltration instruction in the text.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
Sep 11, 2026, 01:48 PM
Package URL
pkg:socket/skills-sh/tenequm%2Fskills%2Facpx-faq%2F@992075d4e525ad2c4154fa1d3ff3ccb3d8f0ea05bea2425151852fb14e89298e
Security Audit — socket — acpx-faq