open-prose

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core idea of an agent language/runtime is plausible, but the actual footprint is overbroad: it installs other skills, executes arbitrary remote programs, propagates database credentials to subagents/logs, and encourages autonomous public GitHub actions. Same-org install evidence reduces the chance of outright malware, but the skill is high risk due to prompt-injection exposure, credential handling, and disproportionate autonomy.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/frames-engineering%2Fskills%2Fopen-prose%2F@68b02dca9ef1f324c4ec6b8812ad85acd5843152