Industry Expert
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent and there is no direct evidence of credential theft, malware, or exfiltration in the pasted content. Risk comes from transitive trust: registry-based installation under an owner namespace not clearly tied to the stated author, plus explicit reliance on multiple other unspecified skills and broad ingestion of untrusted external content, which can enable indirect prompt injection in capable agents.
Confidence: 85%Severity: 57%
Audit Metadata