architect

Warn

Audited by Socket on Jun 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is plausible, but the skill delegates core behavior to a hard-coded third-party MCP server and a remote prompt that effectively becomes system guidance. No direct malware or credential theft is evident, yet the remote prompt/content trust model and optional arbitrary web fetching create meaningful integrity and prompt-injection risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Jun 29, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/mnhkahn%2Fcyeam-cli%2Farchitect%2F@df6bc9ba4d7a5594fec48b6fac744d2980d98b482fc74a1bc8efef9eb8f7f594
Security Audit — socket — architect