journey-loop

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core build/test/refine purpose is coherent, but the skill combines indefinite autonomous looping with runtime ingestion of mutable external gist content that is injected into an execution-capable builder agent. The main risk is indirect prompt injection and uncontrolled iterative action, not clear credential theft or confirmed malware.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/sunfmin%2Fautocraft%2Fjourney-loop%2F@8027cf1cb8e88911c274feab9d23dbb0e817aa09