automatic-stateful-prompt-improver
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareSUSPICIOUS. The stated purpose matches prompt optimization, but the skill’s footprint is broader than a normal prompt helper because it automatically forwards many user requests to an external MCP service and stores performance history over time. The main concern is data flow integrity and scope proportionality: complex, technical, and precision-critical prompts may contain sensitive user data, yet the skill requires blanket pre-response interception and post-task feedback recording without identifying the server operator, endpoint, retention, or trust boundary. No explicit credential theft, exploit behavior, or malware is present, but the external prompt-routing and persistent learning behavior make this a medium risk skill.