skillclaw-skill-evolution

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core behavior mostly matches the stated purpose, but the skill combines an unverifiable install path, API interception, session recording, autonomous skill generation, and cross-agent redistribution. The biggest risk is prompt-injection and trust amplification: untrusted session data can be distilled into shared agent instructions and propagated across a cluster.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 12, 2026, 12:50 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fskillclaw-skill-evolution%2F@f3aa9adb96af54e0e15d392a43ba7fa7a67edf8d