scriptwriter

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/platform.md

This fragment is not executable package code; it documents a workflow that fetches untrusted remote content and persists it into multiple AI coding assistants’ local skill and high-impact instruction files (including system prompts/global rules). No direct malware behavior (exfiltration, execution, credentials) is shown here, but the described unverified remote-to-persistent-instruction pipeline creates a meaningful supply-chain/prompt-injection risk with potentially broad impact across assistants and sessions.

Confidence: 63%Severity: 62%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:59 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Fscriptwriter%2F@6b2751cb06d8d05b0a8cae7ba422add6f4982a0a