self-improve-with-tinyfish

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The TinyFish integration itself is internally consistent and uses official endpoints, but the skill is high-risk because its primary purpose is self-modification: it researches untrusted web content, turns that into persistent instructions, and installs new skills into the agent. This is more suspicious than malicious; the main concerns are transitive skill installation and indirect prompt injection, not credential theft.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
May 13, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/tinyfish-io%2Ftinyfish-cookbook%2Fself-improve-with-tinyfish%2F@803f44cdc44aec3b558f30aa111edce32d462dc1