push-notifications

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS rather than malicious. The core push-notification capabilities and credential needs largely match the stated purpose, and install sources are mostly official or well-known. The main risks are autonomous execution without approval, transitive skill invocation, broad file modification, and out-of-scope telemetry writes to ~/.claude/projects.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fpush-notifications%2F@4f6c125cea1bf831bea08989c960325bea6acf4c
Security Audit — socket — push-notifications