triage

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core triage behavior is coherent, but the skill references transitive external skills and mixes untrusted issue content with command execution during bug reproduction. No direct credential theft or exfiltration is evident, so this is not malware, but it carries medium security risk from transitive trust and prompt-injection exposure.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Jun 18, 2026, 03:35 PM
Package URL
pkg:socket/skills-sh/luizhcrocha%2Fskills%2Ftriage%2F@15be8c751fc73628cc477a17ba48d9f68b8e233ea526cad97a61da63eec31a05
Security Audit — socket — triage