update-readme
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core behavior matches README maintenance, but it expands its trust boundary through multiple transitive skill/agent calls and mixes untrusted web content with write and bash capabilities. No clear credential theft or malicious exfiltration is present, so this is not malware, but the transitive trust chain and prompt-injection exposure make it a medium-risk skill.
Confidence: 84%Severity: 57%
Audit Metadata