vs-rfc-research
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose and capabilities are mostly aligned, but it depends on a third-party MCP server and processes untrusted GitHub content with subagents while retaining file-write capability. This looks like a legitimate research workflow with medium supply-chain and prompt-injection risk, not credential theft or clear malware.
Confidence: 87%Severity: 58%
Audit Metadata