prompt-library

Warn

Audited by Socket on Jul 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose and capabilities mostly align with prompt repository management, but it forwards user-scoped OAuth session tokens to a local script and allows arbitrary alternate API endpoints, creating medium-high credential and data-flow risk. No confirmed malware or hidden exfiltration is shown, but token handling and configurable endpoint routing make the skill riskier than a normal documentation/helper skill.

Confidence: 85%Severity: 69%
Audit Metadata
Analyzed At
Jul 1, 2026, 03:34 PM
Package URL
pkg:socket/skills-sh/broomva%2Fskills%2Fprompt-library%2F@e11bf5d6b5f2ae388fb291c9980c23a52131bdd3ed963ac326352843e89bd483
Security Audit — socket — prompt-library