minding

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior is broadly consistent with a personal graph-memory assistant, but it depends on an externally provided `nks_*` MCP toolchain whose provenance and release trail are not verifiable from the provided evidence. That black-box dependency is granted access to broad personal and cross-realm data, including writes and webhook creation, which is disproportionate to trust without stronger source verification. I found no direct credential-theft, obfuscation, or malicious exfiltration instructions in the skill text itself.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Aug 21, 2026, 07:13 PM
Package URL
pkg:socket/skills-sh/verstak-ai%2Fskills%2Fminding%2F@ef5b147e8391df9c26d27b13393aca7eb1f99dc9603ea54b94fdc92d837a875a
Security Audit — socket — minding