verify-evidence-loop

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Mostly coherent research skill with good HITL and injection-awareness, but its permission footprint is broader than necessary: it combines untrusted web content ingestion with Write and especially Bash access. No credential harvesting, malicious data flow, or suspicious installer behavior is present. Overall this is better classified as suspicious/medium-risk due to indirect prompt-injection exposure and unnecessary execution capability, not malware.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Apr 19, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/ashe-li%2Fagent-skills%2Fverify-evidence-loop%2F@e4eb368e9bec2916912bb64896364281cfb80566