skill-eval
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core behavior matches a skill-evaluation purpose, and there is no direct credential harvesting or download-execute chain. Risk comes from transitive trust in an unverified grader subagent and from evaluating arbitrary skills via spawned agents with broad execution capability, which creates prompt-injection and downstream-execution exposure disproportionate to a simple testing helper.
Confidence: 84%Severity: 64%
Audit Metadata