agent-retro

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is locally scoped and has no external download or exfiltration path, but it reads broad prior conversations and persists derived guidance into USER.md, SOUL.md, AGENTS.md, and MEMORY.md without prior user approval. The main risk is prompt-injection persistence and unsafe autonomous self-modification, not malware.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Mar 25, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/Tangc%2Ftangzhan-skills%2Fagent-retro%2F@4a47b3ea37070d30a1040f2e485a9484af97c3b9
Security Audit — socket — agent-retro