betterprompt

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's main purpose is coherent, but it materially expands trust by installing and running an external CLI, supports `curl|bash`, allows registry endpoint override, and encourages transitive installation of additional remote skills. No clear credential theft or confirmed malware is present, but the trust and prompt-supply-chain footprint is broader than a simple prompt helper and merits medium risk.

Confidence: 79%Severity: 68%
Audit Metadata
Analyzed At
Mar 26, 2026, 07:55 AM
Package URL
pkg:socket/skills-sh/betterpromptme%2Fskills%2Fbetterprompt%2F@a297d427b0caa3c9c3249238cec1b12fd7e6f9e6