prompt-engineering

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
references/prompting-techniques.md

The fragment does not show intentional malware, credential theft, persistence, exfiltration, or sabotage. It does contain a significant unsafe coding pattern: arbitrary LLM-generated text is executed with Python exec without validation or sandboxing. If this tutorial code is copied into an application, prompt injection or compromised model output could achieve arbitrary code execution with the process privileges and access to configured environment credentials. The external API usage is consistent with the documented examples and is not itself suspicious.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 04:10 AM
Package URL
pkg:socket/skills-sh/codealive-ai%2Fai-driven-development%2Fprompt-engineering%2F@542900fbba5dd4aa8da95210b2d88b9982f04ab399194bad99d17a95a3c9ddfc
Security Audit — socket — prompt-engineering