core-dynamic-skills
Warn
Audited by Socket on May 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core inline behavior is mostly coherent with the stated purpose and uses legitimate sources, so this is not malicious on its face. Risk is driven by transitive trust in undocumented companion commands/MCP infrastructure, untrusted docs content being transformed into local skill files, and destructive cleanup operations; overall medium security risk, low malware confidence.
Confidence: 84%Severity: 53%
Audit Metadata