enrich

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core capability matches the stated purpose of knowledge-base enrichment, and there is no malicious installer or obvious credential theft path. However, the skill encourages sending existing internal knowledge to external research services and processing untrusted external content while retaining write access, creating meaningful privacy and prompt-injection risk. Documentation is also internally inconsistent about required tools.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Aug 29, 2026, 06:19 PM
Package URL
pkg:socket/skills-sh/praxstack%2Fskills-and-personas%2Fenrich%2F@cf9aa3e9a7b05b8ab3a60e009bc9b1e9a4bcac0c4d0a55664b601a909c8943c0
Security Audit — socket — enrich