skillclaw-skill-evolution
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core behavior mostly matches the stated purpose, but the skill combines an unverifiable install path, API interception, session recording, autonomous skill generation, and cross-agent redistribution. The biggest risk is prompt-injection and trust amplification: untrusted session data can be distilled into shared agent instructions and propagated across a cluster.
Confidence: 84%Severity: 72%
Audit Metadata