mega-code-wisdom-curate
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated planning/curation purpose is mostly coherent, but the footprint is broader than a simple planner. The main risks are transitive installation of additional skills from remote recommendations, unclear provenance/pinning for the vendor CLI and downstream skills, and external-content-driven execution with Bash/Write access. No confirmed malware or overt credential theft is shown, but the trust chain and data flows warrant medium-high caution.
Confidence: 84%Severity: 79%
Audit Metadata