audit-skill-by-derailment

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose matches its capabilities, and its external network flow is mainly to official GitHub endpoints, so it is not fundamentally deceptive or clearly malicious. The main risk is proportional but nontrivial: it intentionally ingests untrusted skill content from arbitrary repos, launches a subagent on real tasks, and allows command execution plus file edits, creating indirect prompt-injection and operational risk during testing.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 19, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/yigitkonur%2Fskills-by-yigitkonur-secondary%2Faudit-skill-by-derailment%2F@4960ed8df231f8a77bfbd3b12818d1c54706f006
Security Audit — socket — audit-skill-by-derailment