prompt-lab

Fail

Audited by Socket on Mar 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
ground_truth/qra_ics_ot.json

This JSON is not malware and contains no executable malicious code, but it contains high-fidelity, actionable operational security details about F-36 manufacturing systems (device identifiers, CVE/ICS-CERT references, insecure practices, and vendor risk). The primary risk is sensitive information disclosure rather than software-based malicious behavior. Treat the artifact as high-sensitivity intel: restrict access, redact or generalize identifiers before sharing, and ensure downstream QRA generation and storage systems do not publish raw source_text or identifiers to public or uncontrolled sinks.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:49 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fprompt-lab%2F@2ab054fad91f6e79c92cb8899b44a74c6959c1a1
Security Audit — socket — prompt-lab