persona

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core persona/social-intelligence workflow is internally coherent and mostly uses proportional credentials, so it is not overtly malicious. However, it aggregates multiple sensitive data sources for external LLM calls and includes a transitive plugin-install step for preview/image features, which meaningfully increases trust and credential-exposure risk beyond a simple writing-style skill.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:29 AM
Package URL
pkg:socket/skills-sh/b-open-io%2Fprompts%2Fpersona%2F@4a350b1896922a4f1777ca5193eab1d1050c68c9