infinite-gratitude
Warn
Audited by Socket on Apr 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The visible skill is mostly a launcher for an external, unpinned GitHub repository, so its real capabilities cannot be verified here. The stated purpose is plausible, but the trust model is weak and the multi-agent web-research pattern raises prompt-injection risk if the downstream repo has broad permissions.
Confidence: 79%Severity: 76%
Audit Metadata