analyze-experiment

Warn

Audited by Socket on Jul 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and requested data access fit experiment analysis, but its trust model depends on an unverifiable externally installed `tpc` CLI obtained through a raw `curl|bash` installer. Because that CLI is authenticated and handles sensitive run/transcript data, the install and credential-forwarding risk is high even without direct evidence of malicious exfiltration.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Jul 26, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/promptingcompany%2Fagent-skills%2Fanalyze-experiment%2F@a26f223d432b9cdb27a7be298b4ec67864373c912417d4234419cf1c51f10929
Security Audit — socket — analyze-experiment