audit-skill-by-derailment

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose matches its capabilities, and its external network flow is mainly to official GitHub endpoints, so it is not fundamentally deceptive or clearly malicious. The main risk is proportional but nontrivial: it intentionally ingests untrusted skill content from arbitrary repos, launches a subagent on real tasks, and allows command execution plus file edits, creating indirect prompt-injection and operational risk during testing.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 17, 2026, 10:41 PM
Package URL
pkg:socket/skills-sh/yigitkonur%2Fskills-by-yigitkonur%2Faudit-skill-by-derailment%2F@cb9c4356fc8191f5faf9d1ddaae792c58283678d
Security Audit — socket — audit-skill-by-derailment