load-context
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: mostly coherent as a context-loading skill, but its footprint is broader than necessary because it can read arbitrary local paths and import arbitrary remote web content directly into the conversation. No clear malware or credential-harvesting behavior appears, and GitHub API usage is official, but the unrestricted content-loading design creates medium risk through prompt-injection and unintended local data exposure.
Confidence: 84%Severity: 57%
Audit Metadata