hackathon-judging

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core Kaggle data access is legitimate and aligned with hackathon judging, but the skill materially expands risk by directing an agent to process large amounts of untrusted external content, use browser automation, and depend on a third-party eval skill/repo. No clear credential theft or malicious exfiltration is present, but the prompt-injection and trust-chain risks are significant for an AI agent workflow.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 06:59 PM
Package URL
pkg:socket/skills-sh/Kaggle%2Fkaggle-skills%2Fhackathon-judging%2F@e9864b278503a98b327ab3650bf198cdea826560255bd4ba86011bea7e51635e
Security Audit — socket — hackathon-judging