healthcare-audit
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated audit purpose is plausible, but the skill is over-scoped for a compliance review because it enforces autonomous execution, chains unverified sub-skills, includes a self-healing fix-validation loop that conflicts with its own 'do not modify code' rule, and silently writes telemetry to Claude memory. There is no confirmed malware or explicit external credential-exfiltration path in this skill alone, but the transitive trust and autonomous-action profile make it high-risk.
Confidence: 87%Severity: 72%
Audit Metadata