prd-loader

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent for a PRD loader, but the skill is riskier than necessary because it prefers invoking unspecified other skills/MCP servers and can fetch arbitrary external content while retaining write/edit/bash-capable execution context. No direct credential harvesting or malicious exfiltration is shown, but transitive trust and prompt-injection exposure make it medium risk.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 13, 2026, 11:28 AM
Package URL
pkg:socket/skills-sh/unfallenwill%2Fquickspec%2Fprd-loader%2F@d10724ce6e50bd98da5c46b569174c5258c91f02