interview-simulator

Warn

Audited by Socket on Sep 18, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose, credentials, and data flows are broadly consistent with building an interview simulator, but the installation trust chain is incomplete because the core application comes from an unspecified repo and then runs `npm install` with access to sensitive API keys. No clear malicious exfiltration or off-purpose behavior is shown, but the unverifiable repo/dependency path creates meaningful supply-chain risk.

Confidence: 89%Severity: 57%
AnomalyLOW
references/session-orchestration.md

No clear malicious behavior is present in the shown fragment. It implements legitimate interview-training functionality, but it processes and externally transmits highly sensitive user data and places untrusted transcript content directly into an AI prompt. Model output and database inputs require validation and authorization controls. The empty-weakness handling also contains a reliability defect. The assessment is limited because the file is truncated.

Confidence: 94%Severity: 57%
Audit Metadata
Analyzed At
Sep 18, 2026, 12:15 AM
Package URL
pkg:socket/skills-sh/curiositech%2Fsome_claude_skills%2Finterview-simulator%2F@87860c02ab304f10a8c3b946076bbc120f0cd9e23d245f4302125a9d9c18059c
Security Audit — socket — interview-simulator