swift-concurrency

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
es/index.md

This fragment is a high-risk supply-chain/prompt-injection installer: it downloads unverified Markdown instruction/skill content from a hardcoded remote URL and persists it into user and project directories used by AI coding agents. While no classic malware actions (shell/exfiltration) are shown in the snippet, the unvalidated remote-to-agent-instruction flow makes altered or malicious remote content a credible security threat.

Confidence: 75%Severity: 78%
Audit Metadata
Analyzed At
Sep 5, 2026, 03:14 AM
Package URL
pkg:socket/skills-sh/tuist%2Ffuckingapproachableswiftconcurrency%2Fswift-concurrency%2F@3de6924cfedc8807928803b93ae949e7c3641f53eb23d57d3f9f9c4b4433aa8c