soia-meta-prompt-clarity
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill's core prompt-authoring behavior is coherent and it does not show credential theft or exfiltration. However, its installation model extends trust to a third-party skills repository and includes a wildcard-permission npx install path, which is broader than necessary for this purpose and creates medium supply-chain and transitive-trust risk.
Confidence: 89%Severity: 72%
Audit Metadata