skill-review
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
AnomalyAnomalyevals/purpose-fail/SKILL.md
LOWAnomalyLOW
evals/purpose-fail/SKILL.md
SUSPICIOUS. The skill is not overtly malicious and names no external installs, credentials, or network endpoints, but its scope is poorly bounded: 'improve the whole agent toolkit' and 'decide for yourself' grant disproportionate autonomy relative to the vague purpose. The main risk is overreach and unintended modification of unrelated skills or workflows, not confirmed malware or credential theft.
Confidence: 90%Severity: 58%
Audit Metadata