bentolabs-ai
Warn
Audited by Socket on Jun 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is narrowly scoped to BentoLabs API usage, but its trust chain is inconsistent: it asks users to source the API key from app.vm0.ai rather than a clearly verified bentolabs.ai-controlled flow. That makes the skill suspicious on data-flow integrity grounds, though not overtly malicious.
Confidence: 84%Severity: 62%
Audit Metadata