prp-core-runner

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches PRP workflow orchestration, but the skill grants autonomous write actions (implement, commit, open PR) through an unverified underlying slash command whose implementation is not shown. No direct credential theft or exfiltration is evident, yet the hidden command and one-shot automation create meaningful execution and real-world action risk.

Confidence: 79%Severity: 64%
Audit Metadata
Analyzed At
Apr 17, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/Wirasm%2FPRPs-agentic-eng%2Fprp-core-runner%2F@8b2d63c2cbd45294f43edb270dbdca8fe40ffae9