load-context

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent as a context-loading skill, but its footprint is broader than necessary because it can read arbitrary local paths and import arbitrary remote web content directly into the conversation. No clear malware or credential-harvesting behavior appears, and GitHub API usage is official, but the unrestricted content-loading design creates medium risk through prompt-injection and unintended local data exposure.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fload-context%2F@422001624c06a22e4ff6cf385cb8958211ebc8a1
Security Audit — socket — load-context