loom-skill-enhancement
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
AnomalyAnomalyreference/packages.beta.md
LOWAnomalyLOW
reference/packages.beta.md
This is a readable offline runtime/package policy with no direct malicious payload or apparent data theft. It does authorize downloading and executing external beta binaries and assemblies. The mutable GitHub .latest fallback and absence of concrete embedded hash/signing anchors create a meaningful supply-chain risk; exact immutable package acquisition and independently verified digests should be enforced. The fragment alone does not establish malware in the referenced packages.
Confidence: 96%Severity: 62%
Audit Metadata