self-learning

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose, but its main risk is indirect prompt injection: it converts untrusted web content into a new persistent skill, effectively extending agent behavior through scraped instructions. No evidence of credential theft, third-party credential forwarding, or malicious payload delivery was found. Risk is medium due to transitive trust and persistence, not confirmed malware.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Mar 16, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/WhizZest%2Fself-learning-skill%2Fself-learning%2F@bee84310a9d253cac6fdfefcf99b3a2ce92a5f1f