good-morning
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill itself is small and has no installer or credential harvesting, but it is overly permissive because it delegates full authority to a local `goodmorning.md` and instructs the agent to follow it exactly. The main risk is indirect prompt injection and uncontrolled actions from untrusted workflow content, not malware or supply-chain behavior in the skill text itself.
Confidence: 89%Severity: 68%
Audit Metadata