rubber-duck
Warn
Audited by Socket on Jun 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is broadly aligned with its stated purpose: getting an independent AI critique via another model family. The main risk is not hidden malware behavior but deliberate delegation of potentially sensitive project context to other installed agent CLIs and their upstream APIs, plus broad local discovery of AI tooling. This is better classified as suspicious/high-vulnerability than malicious because the data flow is intentional and disclosed, but the trust boundary is wide and depends on external CLIs the skill does not validate.
Confidence: 83%Severity: 61%
Audit Metadata