oss-skill

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent, but it mixes broad untrusted-content ingestion with file creation and helper-script execution, creating meaningful indirect prompt-injection risk. No clear credential harvesting or malicious exfiltration is present, so this looks like a high-risk research/automation skill rather than confirmed malware.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 18, 2026, 11:55 PM
Package URL
pkg:socket/skills-sh/lianchi%2Foss-skill%2Foss-skill%2F@b535f489f3e93f3260b6b53443b8b71681b80a79