automatic-stateful-prompt-improver
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose matches prompt optimization, but its footprint is broader than necessary because it automatically forwards many user prompts—including potentially sensitive domains—to an external learning MCP service and stores feedback/history without clear privacy or retention constraints. Supply-chain risk is moderate rather than high because the referenced backend has public source and there is no raw download-execute path shown, but the undocumented MCP trust boundary keeps this above benign.
Confidence: 85%Severity: 57%
Audit Metadata