zr-inbox
Warn
Audited by Socket on May 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The stated purpose is coherent for an inbox-handling skill, but it relies on an unverifiable external `probe` CLI and executes router-provided context commands. Data flow is limited to reading messages/directives and sending replies, with no clear credential theft or exfiltration, but the undisclosed backend and command execution path make the skill high-risk enough to avoid a benign classification.
Confidence: 82%Severity: 72%
Audit Metadata