mistral

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is plausible, but its actual footprint centers on a third-party `x-cmd` wrapper that receives Mistral API keys and file contents. The Mistral docs do reference this wrapper, which lowers malicious certainty, but the trust boundary mismatch plus remote-script installation and credential forwarding make the skill high risk for an AI agent.

Confidence: 87%Severity: 80%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fmistral%2F@d5c99ba6bdfdf4c2edb118b3305da66fc1e7e346
Security Audit — socket — mistral