crisis-risk-monitor
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core audit purpose broadly matches the requested file-reading behavior, but the skill expands scope with autonomous full-codebase investigation, silent local telemetry writes, and recommendations to invoke additional unreviewed slash commands. There is no clear external exfiltration or malicious payload, so this is not confirmed malware, but it carries moderate security risk from hidden local writes and transitive skill execution.
Confidence: 90%Severity: 58%
Audit Metadata