prompt-agent

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s behavior is broadly consistent with a security-audit tool, but it relies on a remote download/install chain from a custom vendor release domain, has an acknowledged bootstrap trust gap, and establishes persistent scheduled execution. I found no strong evidence of credential theft, third-party interception, or purpose-incompatible access, so this is not malicious; the main concern is install-trust and persistence rather than data exfiltration.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/prompt-security%2Fclawsec%2Fprompt-agent%2F@83a53854198f85844954ccf6f4ae267bf641b0e1