skill-optimizer

Warn

Audited by Socket on Sep 23, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's main purpose and capabilities are broadly aligned and it does not request credentials or exfiltrate data, but it normalizes risky supply-chain behavior by directing users to clone and run third-party code from a personal GitHub repo with unpinned dependencies. The pre-execution shell syntax is discussed only as documentation, not embedded as an active load-time payload.

Confidence: 90%Severity: 56%
AnomalyLOW
eval-viewer/viewer.html

No clear indicators of intentional malware/backdoor behavior are visible in this fragment. However, there are significant security risks typical of supply-chain content rendering: (1) DOM XSS potential due to container.innerHTML fed by a large HTML string constructed from EMBEDDED_DATA with not all interpolated fields verifiably escaped, and (2) potential malicious content loading via iframe.src set to file.data_uri without visible sandboxing or scheme restrictions. If EMBEDDED_DATA or file.data_uri can be attacker-controlled, this module should be treated as high-risk and reviewed for strict escaping, URI validation, and safe rendering/sandboxing.

Confidence: 55%Severity: 68%
Audit Metadata
Analyzed At
Sep 23, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Fskill-optimizer%2F@ab3e34d890815d2b29a740c7c3566a29f25a930bdb50d302f5597c43d6852b92
Security Audit — socket — skill-optimizer