ringdown
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core Ringdown relay behavior is aligned with the stated purpose, but the skill routes conversation data and bearer-authenticated messages through a third-party service and can upload oversized payloads to an unrelated public host (`0x0.st`). No confirmed malware or hidden execution is present, but the external data-routing footprint is broader than a typical collaboration skill and creates meaningful confidentiality risk.
Confidence: 92%Severity: 61%
Audit Metadata