update-acumen

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its behavior, but that behavior is inherently risky because it installs/syncs unpinned third-party skills from a mutable GitHub repo into active agent skill directories. This is mainly a transitive trust and supply-chain risk, not confirmed malware.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Apr 27, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/VGrss%2Facumen%2Fupdate-acumen%2F@d1a498e5417e0e681dee1214d71afdb604655e8a
Security Audit — socket — update-acumen