engineering-advanced-skills

Warn

Audited by Socket on May 14, 2026

5 alerts found:

Anomalyx4Security
AnomalyLOW
agenthub/SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated purpose and does not show clear credential theft or exfiltration, but it grants high-impact autonomous repository actions, executes arbitrary evaluation commands, and has some install/publisher provenance ambiguity. Overall this looks like a legitimate engineering orchestration skill with medium operational risk rather than malware.

Confidence: 81%Severity: 58%
AnomalyLOW
SKILL.md

SUSPICIOUS. This index file is mostly benign on its face, but it delegates behavior to 25 unreviewed sub-skills and is distributed through a third-party personal marketplace/repo with documented remote-install patterns upstream. The excerpt itself shows no credential theft or exfiltration, so malware confidence stays low, but the transitive trust and supply-chain exposure make overall risk moderate.

Confidence: 81%Severity: 56%
AnomalyLOW
browser-automation/SKILL.md

Classificação: SUSPICIOUS. A skill é majoritariamente coerente com automação web legítima e usa ecossistema oficial do Playwright, sem instaladores obscuros ou exfiltração explícita. Ainda assim, os padrões anti-detecção/evasão, o uso de sessões autenticadas locais e a combinação de leitura de conteúdo web não confiável com capacidade de agir no navegador elevam o risco acima de benigno.

Confidence: 84%Severity: 56%
AnomalyLOW
helm-chart-builder/SKILL.md

SUSPICIOUS: the core Helm-chart functionality is coherent and locally scoped, with no credential harvesting or exfiltration behavior, but the install trust story is inconsistent. The declared publisher does not match the GitHub source, and installation relies on an unpinned repo clone plus unsigned local scripts, making this a supply-chain concern rather than confirmed malware.

Confidence: 88%Severity: 56%
SecurityMEDIUM
autoresearch-agent/SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, but it grants an AI agent unusually broad autonomous authority to edit arbitrary files, execute arbitrary evaluation commands, and persist changes indefinitely. The install path is only moderately trustworthy due to mutable GitHub clone instructions and publisher mismatch, and the autonomy level is disproportionate enough to make this a high-risk skill even without clear exfiltration behavior.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
May 14, 2026, 01:16 PM
Package URL
pkg:socket/skills-sh/ricardonevesbraga%2Fflowgrammers-skills%2Fengineering-advanced-skills%2F@f2d2536f0b06f2cb80a03213e1f1d1a34667efd3
Security Audit — socket — engineering-advanced-skills