improve
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its stated repo-improvement purpose, and there is no obvious credential theft or third-party installer abuse. The main risk is autonomous operation combined with external research ingestion and the ability to modify files, run commands, and commit changes, which creates a significant indirect prompt-injection and unwanted-action surface.
Confidence: 88%Severity: 68%
Audit Metadata