ae-community
Warn
Audited by Socket on May 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s functional scope matches community analytics, but it requires an unverifiable external CLI and forwards tokens to it, including access to cached local credentials and a claimed browser-token extraction flow. Data routing mostly appears consistent with ThinkingData, yet the binary provenance is not publicly verifiable, so the risk is high even without stronger evidence of malicious intent.
Confidence: 87%Severity: 84%
Audit Metadata