auto-skill

Warn

Audited by Socket on Sep 10, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core memory/knowledge-base behavior is plausible, but the skill’s actual footprint is not proportionate because it tries to make itself mandatory across all tasks and persist by editing global IDE instructions. The only external install is optional and medium-risk, but the stronger concern is unauthorized persistence and broad behavioral control.

Confidence: 94%Severity: 82%
AnomalyLOW
references/auto-skill.md

No clear evidence of classic malware (no network exfiltration, credential theft, command execution) is present in the provided fragment. However, the protocol explicitly performs durable persistence by modifying a global configuration file (~/.claude/CLAUDE.md) to force a “task启动协议” on every future session, and it maintains growing local knowledge/experience stores. This persistent self-bootstrap behavior is the main supply-chain security concern (behavioral lock-in/privacy/data-retention risk) even though malicious payload indicators are not shown. Overall: treat as a potentially unsafe persistence/memory agent unless implementation details confirm strict safety boundaries.

Confidence: 52%Severity: 55%
Audit Metadata
Analyzed At
Sep 10, 2026, 10:03 AM
Package URL
pkg:socket/skills-sh/frizzlefur%2Fflowkit%2Fauto-skill%2F@29cf75775f72cca244e615d0b655340d7d00456031ab03944510d11699848101
Security Audit — socket — auto-skill