community-signal-digest

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main behavior is coherent with community monitoring, and there is no strong sign of malware or credential theft. However, trust in key non-public tools like Tiger Den/Tiger Docs is not independently verifiable from the evidence, the skill processes untrusted external content with optional fetch/enrichment, and it auto-drafts public responses plus writes persistent records, which raises moderate operational and prompt-injection risk.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
May 5, 2026, 07:21 AM
Package URL
pkg:socket/skills-sh/timescale%2Fmarketing-skills%2Fcommunity-signal-digest%2F@5710c560efa91b65a4366e04d7b1ff85051e4e30