process-dedup-review
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose and data handling are mostly coherent for a process dedup review workflow, and its remote enrichment uses same-ecosystem TianGong credentials. However, the core functionality delegates to an external tiangong CLI whose official provenance and install path were not verified from the available evidence, yet that CLI receives API credentials and performs network calls. That supply-chain trust gap is the main driver of risk, not confirmed malicious behavior.
Confidence: 84%Severity: 76%
Audit Metadata