audit-plugin
Fail
Audited by Socket on May 24, 2026
2 alerts found:
AnomalyObfuscated FileAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is plausible for an auditing skill, but the actual execution relies on an unverifiable transitive skill/analyzer and gives the agent Bash+Write authority over untrusted plugin content in an iterative fix loop. The main concern is install/execution trust and indirect prompt-injection risk from analyzing arbitrary skills, not confirmed malware.
Confidence: 100%Severity: 60%
Obfuscated Filereferences/acceptance-criteria.md
HIGHObfuscated FileHIGH
references/acceptance-criteria.md
All provided reports lack the actual code to review, rendering malware/security-risk assessment incomplete. An improved approach is to obtain the code bundle and apply targeted checks against the acceptance criteria, then provide a concrete remediation plan.
Confidence: 90%
Audit Metadata