sigil

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose matches its local codebase-analysis and skill-generation behavior, and there are no clear exfiltration or installer red flags. The main risk is that it reads large amounts of potentially untrusted repository content and then writes new persistent agent skills, creating indirect prompt-injection and transitive-capability expansion risk that is significant but still coherent with the claimed purpose.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 10:17 AM
Package URL
pkg:socket/skills-sh/simota%2Fagent-skills%2Fsigil%2F@41b64a10e0e147b6b3001b2bdc947953acac2638