second-opinion
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is purpose-aligned and uses official same-org CLIs, so it does not look malicious. Risk is elevated because it exports local code to external LLM providers, installs GitHub-hosted extensions, and runs Gemini with --yolo, which can auto-approve tool actions during analysis.
Confidence: 89%Severity: 67%
Audit Metadata