product-roadmap
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose and capabilities are largely aligned, and its GitHub data flow is direct and proportionate. The main concern is install/execution trust: it requires unverifiable nks_* MCP tooling and implicitly trusts sibling skills without a verifiable publisher/source chain, which forces a high security-risk classification despite no clear signs of malware or credential theft.
Confidence: 84%Severity: 72%
Audit Metadata