reputation-patterns

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The scoring logic matches the stated reputation-management purpose, and there is no clear exfiltration path, but the skill references a local Canavar CLI/script whose provenance is not verifiable from official same-org sources. It also normalizes autonomous/QA-skip behavior for top-tier agents, which raises operational risk even without explicit malicious behavior.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 13, 2026, 10:41 PM
Package URL
pkg:socket/skills-sh/vibeeval%2Fvibecosystem%2Freputation-patterns%2F@0c8470ab29c07fda167193a7b9487dcc5b9eb1ba
Security Audit — socket — reputation-patterns