architect
Warn
Audited by Socket on Jun 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is plausible, but the skill delegates core behavior to a hard-coded third-party MCP server and a remote prompt that effectively becomes system guidance. No direct malware or credential theft is evident, yet the remote prompt/content trust model and optional arbitrary web fetching create meaningful integrity and prompt-injection risk.
Confidence: 82%Severity: 58%
Audit Metadata