curator

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent, and its network targets appear consistent with GitHub/local vault usage, but it grants a powerful agent broad read/write/exec capabilities to autonomously ingest untrusted repository content and persist learned outputs. Main risk is indirect prompt injection and over-broad autonomous execution, not confirmed malware or credential harvesting.

Confidence: 83%Severity: 63%
Audit Metadata
Analyzed At
May 3, 2026, 11:07 AM
Package URL
pkg:socket/skills-sh/alfredolopez80%2Fmulti-agent-ralph-loop%2Fcurator%2F@2105129a86f1e68d406a663497618a2dd1675f38
Security Audit — socket — curator