New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

Skill: Data exfiltration

Severity

High

Short Description

AI agent skill accesses sensitive data such as environment variables, credentials, or home directory files and may transmit them to external endpoints.

Suggestion

Review the skill's code and behavior carefully. Ensure the detected patterns are intentional and safe before allowing this skill to run.