pitfall-experience

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the GitHub integration itself is plausible, but the skill is overpowered for a troubleshooting reference tool. It reads a local token file, mandates autonomous issue creation, and most importantly converts untrusted GitHub capsule content into executable remediation guidance, creating a high indirect prompt-injection risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 18, 2026, 09:36 AM
Package URL
pkg:socket/skills-sh/BENZEMA216%2Fai-ecommerce-agent-skills%2Fpitfall-experience%2F@b4500db7783bdb19421bfda214cb9b4505d343bf
Security Audit — socket — pitfall-experience