prompt-library
Warn
Audited by Socket on Jul 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core purpose and capabilities mostly align with prompt repository management, but it forwards user-scoped OAuth session tokens to a local script and allows arbitrary alternate API endpoints, creating medium-high credential and data-flow risk. No confirmed malware or hidden exfiltration is shown, but token handling and configurable endpoint routing make the skill riskier than a normal documentation/helper skill.
Confidence: 85%Severity: 69%
Audit Metadata