survey-generator

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core survey-writing behavior is coherent, but the skill mixes arbitrary WebFetch input with Write+Bash and forwards prompts/credentials to provider-selected endpoints, including third-party or custom gateways. Main risk is indirect prompt injection and credential/data routing beyond official APIs, not confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 12:23 PM
Package URL
pkg:socket/skills-sh/rohitg00%2Fpro-workflow%2Fsurvey-generator%2F@2c69a6c744a2a6702723c699dfc5c48e1535b649