pet-groomer

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/platform-support.md

This snippet documents a high-impact supply-chain/prompt-persistence mechanism: it fetches untrusted remote content from a raw GitHub URL and instructs installing/appending it into multiple assistants’ persistent configuration, including global rule files and a Codex system_prompt-like field. No direct malware actions are shown in the snippet itself, but the persistence pattern creates substantial risk if the remote SKILL.md contains malicious instructions. Treat as medium-to-high security risk until the referenced SKILL.md content and installer behavior (including any integrity checks) are reviewed.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:58 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Fpet-groomer%2F@ab6a5ffd12a40e3f9a28b68d62066821f729664e
Security Audit — socket — pet-groomer