llm-models
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core purpose is coherent, but the footprint is enlarged by transitive skill installation and remote installer execution. Same-org documentation, official-looking domains, and checksum/signature verification signals argue against confirmed malware, yet the mixed publisher namespaces and install chain make this higher trust risk than a normal API reference skill.
Confidence: 84%Severity: 67%
Audit Metadata