research-plan-implement
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core purpose is coherent, and it does not show overt credential theft, hidden exfiltration, or suspicious installers. The main risks come from transitive invocation of other skills plus a web-research-to-implementation pipeline that can expose the agent to indirect prompt injection before taking code-writing actions, though explicit approval gates and scoped orchestration reduce the likelihood of malicious intent.
Confidence: 84%Severity: 56%
Audit Metadata