loom-skill-enhancement
Warn
Audited by Socket on Jul 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The stated purpose and capabilities mostly align, but the skill’s default workflow depends on external Loom package binaries whose provenance is not established in the provided text. There is no clear credential harvesting or malicious exfiltration, but the unverifiable runtime/install path creates meaningful supply-chain risk.
Confidence: 78%Severity: 62%
Audit Metadata