research
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s overall goal is benign research/reporting, and there is no strong evidence of credential theft or malware. However, it is internally inconsistent: it declares no tools while directing the agent to use shell commands, web search, task tooling, file writes, and another skill. Its largest real risk is indirect prompt injection from untrusted web/GitHub content plus transitive trust in `docs-seeker`, not overt exfiltration.
Confidence: 89%Severity: 57%
Audit Metadata