prophet-growth-agent

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is plausible, but it relies on Playwright to harvest a live Privy JWT from browser localStorage, forwards that token for API use, and persists outputs to a separate Seren service. Those behaviors are somewhat aligned with the workflow but broader and riskier than a lightweight growth-check/reminder skill should need. No confirmed malware or overt exfiltration endpoint is present, but the token-handling and third-party storage design create meaningful medium risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/serenorg%2Fseren-skills%2Fprophet-growth-agent%2F@0c60cf490f1ff7b26607a4176ced66dd9d5fb09c