audit-oe

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated purpose: it audits biomedical citations and writes a report. Main concerns are reliance on an unofficial OpenEvidence MCP and the high indirect prompt-injection surface created by fetching and processing untrusted external content with write-capable orchestration. This looks suspicious from a security-hardening perspective, but not malicious or obviously credential-harvesting.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Apr 20, 2026, 02:34 PM
Package URL
pkg:socket/skills-sh/htlin222%2Faudit-oe-skill%2Faudit-oe%2F@86f8976235801e90502ec1949ff6236b0e606223
Security Audit — socket — audit-oe