tour-guide

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/platform-support.md

This fragment describes a cross-platform, persistent installation mechanism that fetches unverified remote Markdown and injects it into privileged assistant configuration contexts (including system prompts/global rules). No executable malware is shown in this excerpt, but the pattern presents a meaningful supply-chain/prompt-injection integrity risk if the remote artifact is tampered with. Review and pin/verify the referenced SKILL.md content before installation.

Confidence: 62%Severity: 64%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:59 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Ftour-guide%2F@25ca27c7fef9d4fa25b1712a74e43937e31ccda2