incident-responder
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS rather than malicious. The stated purpose broadly matches incident-response capabilities, but the footprint is underspecified: referenced automation scripts are not shown, integrations lack data-flow detail, and external evidence suggests a transitive skills-CLI install path without strong release verification. No confirmed credential theft, covert behavior, or dangerous pre-execution commands are present.
Confidence: 79%Severity: 56%
Audit Metadata