prompt-agent
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the skill’s behavior is broadly consistent with a security-audit tool, but it relies on a remote download/install chain from a custom vendor release domain, has an acknowledged bootstrap trust gap, and establishes persistent scheduled execution. I found no strong evidence of credential theft, third-party interception, or purpose-incompatible access, so this is not malicious; the main concern is install-trust and persistence rather than data exfiltration.
Confidence: 83%Severity: 58%
Audit Metadata