always-init
Fail
Audited by Socket on Feb 16, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
[Skill Scanner] Detected system prompt override attempt The 'always-init' skill's purpose is plausible (centralized context for personalization), but the required global-first invocation and unconditional local file read present a significant design-level security risk. The artifact does not contain obvious active malware code, but its proposed integration pattern would greatly increase the chance of accidental or deliberate exfiltration of sensitive data. If implemented, it must be redesigned with least-privilege, access control, redaction, and explicit consent to mitigate high exposure.
Confidence: 95%Severity: 90%
Audit Metadata