mega-code-wisdom-curate

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated planning/curation purpose is mostly coherent, but the footprint is broader than a simple planner. The main risks are transitive installation of additional skills from remote recommendations, unclear provenance/pinning for the vendor CLI and downstream skills, and external-content-driven execution with Bash/Write access. No confirmed malware or overt credential theft is shown, but the trust chain and data flows warrant medium-high caution.

Confidence: 84%Severity: 79%
Audit Metadata
Analyzed At
Apr 10, 2026, 04:13 AM
Package URL
pkg:socket/skills-sh/wisdomgraph%2Fmega-code%2Fmega-code-wisdom-curate%2F@8529b56c30aa890cb6ee0569a678ac853b833c13