prose

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core VM/execution behavior fits the skill's stated purpose, and the install steps for PostgreSQL tooling are mostly standard and verifiable. The main concerns are proportionality and data flow: the skill can fetch and execute remote `.prose` programs from arbitrary URLs or an insufficiently verified registry host, and postgres mode intentionally passes database credentials into subagent contexts and logs. This is not confirmed malware, but it meaningfully expands execution and credential exposure beyond a low-risk documentation skill.

Confidence: 89%Severity: 71%
Audit Metadata
Analyzed At
Sep 4, 2026, 06:56 AM
Package URL
pkg:socket/skills-sh/deepgram%2Fdglabs-deepclaw%2Fprose%2F@3107ba7c53e6a1f3d7c4ef1f4444fe805bd1ef988b53608bfd79fad4935107a5
Security Audit — socket — prose