auto-skill

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s main function is presented as memory management, but its actual footprint includes self-prioritization, background operation, and persistent modification of global agent rule files across environments. There is no clear exfiltration or malware payload, yet the self-installing prompt persistence and unprompted config edits are not proportionate to the stated purpose.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Apr 8, 2026, 10:51 AM
Package URL
pkg:socket/skills-sh/changgenglu%2Fchanggenglu-blog%2Fauto-skill%2F@792a3c10b63702c7494c14c43066f1d20da9e001