upstream-sync

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it grants an AI agent the ability to pull untrusted upstream repository content and apply local code/file changes, with moderate supply-chain and indirect prompt-injection risk. No direct credential harvesting, exfiltration endpoint, or malicious installer is evident from the supplied text, but the unseen upstream registry and live unpinned sync behavior keep risk above benign.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:45 PM
Package URL
pkg:socket/skills-sh/techwavedev%2Fagi-agent-kit%2Fupstream-sync%2F@356d510d4ce1e2c15e05fb668f64c9245d47e1c6
Security Audit — socket — upstream-sync