upstream-sync
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but it grants an AI agent the ability to pull untrusted upstream repository content and apply local code/file changes, with moderate supply-chain and indirect prompt-injection risk. No direct credential harvesting, exfiltration endpoint, or malicious installer is evident from the supplied text, but the unseen upstream registry and live unpinned sync behavior keep risk above benign.
Confidence: 83%Severity: 58%
Audit Metadata