xy-coach
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core behavior mostly matches the stated coaching purpose, but the trust model is weaker than a benign low-risk skill: it executes unverifiable local repo scripts and, in external mode, can forward user business context to any configured 'OpenAI-compatible' API rather than a fixed official endpoint. No clear credential harvesting or overtly malicious behavior is shown, but install/provenance gaps and unconstrained third-party data routing make the skill medium risk.
Confidence: 84%Severity: 66%
Audit Metadata