product-prd

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core PRD-authoring purpose is coherent, but its footprint is broader than a pure writing helper because it can fetch untrusted external content, write files, execute local commands, and invoke other skills. Main concerns are indirect prompt-injection exposure and transitive trust via delegated skills; install-trust risk is moderate mainly due to the ambiguous `jira` CLI reference, not confirmed malicious behavior.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Aug 31, 2026, 08:42 PM
Package URL
pkg:socket/skills-sh/mgiovani%2Fcc-arsenal%2Fproduct-prd%2F@752488e0dcacfba18aceadadd29c9c8360044de1e01a05192dccc094c72c9f78
Security Audit — socket — product-prd