Known Vulnerable Dependency: nanoid==5.0.4 — 1 advisory(ies): CVE-2024-55565 (Predictable results in nanoid generation when given non-integer values)
Low
- Category
- Supply Chain
- Confidence
- 89% confidence
- Finding
- nanoid==5.0.4
Security audit
Security checks across malware telemetry and agentic risk
The skill appears to be a narrowly scoped local review-queue helper, with only a dependency hygiene issue to consider.
This looks acceptable to install if you want a local file-based human-review queue. Review that ~/.arbiter/queue/ may contain decision context from your agent sessions, keep that directory private, and prefer an updated release that bumps nanoid before relying on queue IDs for anything security-sensitive.
60/60 vendors flagged this skill as clean.
No suspicious patterns detected.