skill-benchmark

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, and its external dependency is the official Anthropic CLI, but it materially increases execution risk by spawning nested headless agent sessions with permissions bypassed and Bash access. This is proportionate to benchmarking only if used on trusted skills/tasks; for arbitrary or untrusted inputs, prompt-injection and unsafe autonomous execution risk are significant.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
May 11, 2026, 05:07 PM
Package URL
pkg:socket/skills-sh/workersio%2Fskills%2Fskill-benchmark%2F@d5168bf6cdd6b509d379e36d432ddbfe8c24d852