create

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the router's stated purpose is coherent and it has no direct exfiltration behavior, but it introduces medium risk by instructing installation of third-party companion plugins based on unvalidated recommendation metadata. Main concern is transitive trust and marketplace provenance, not confirmed malware.

Confidence: 91%Severity: 61%
Audit Metadata
Analyzed At
Apr 15, 2026, 04:47 PM
Package URL
pkg:socket/skills-sh/VeryGoodOpenSource%2Fvgv-wingspan%2Fcreate%2F@206bd7b249ddc666719814bacc4f4402cbfba314