curator-repo-learn

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and its external network use is limited to normal GitHub cloning, but it analyzes arbitrary untrusted repositories while holding Bash, Write, and Task permissions. That makes indirect prompt injection and unpinned external content the main risks; there is no clear evidence of credential theft, third-party proxying, or malicious install behavior in the provided text.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
May 3, 2026, 11:07 AM
Package URL
pkg:socket/skills-sh/alfredolopez80%2Fmulti-agent-ralph-loop%2Fcurator-repo-learn%2F@fd94913e4c70e094580927a008a705e7836f698a