skill-auditor

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but its footprint is broad: it reads untrusted skill content, may execute bundled scripts or call documented APIs, and writes modified outputs. This creates substantial transitive-trust and indirect prompt-injection risk even without clear malicious intent in the auditor itself.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:15 PM
Package URL
pkg:socket/skills-sh/aipoch%2Fmedical-research-skills%2Fskill-auditor%2F@ccd9da38009dd50626322d9c11d42f3eebfc226b