prompt-authoring

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is benign and the runtime behavior described in the skill is narrowly scoped to prompt authoring, but the skill asks the agent to perform a transitive remote installation from an unpinned personal GitHub repo. That makes install trust the main issue; there is no clear evidence of credential theft or malicious data routing in the skill content shown.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Mar 13, 2026, 01:06 AM
Package URL
pkg:socket/skills-sh/aelaguiz%2Fauthoring-skills%2Fprompt-authoring%2F@d6e60dbd3c23bbe8aeeb5678abff0b2dffb064a2