rlm

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose mostly matches its capabilities, but it meaningfully expands autonomy and exposes the agent to indirect prompt injection by processing large amounts of untrusted code with shell and sub-agent access. No clear credential theft, exfiltration endpoint, or incompatible capability is present, so this is not malicious; the main concern is elevated operational risk from recursive multi-agent code analysis.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 3, 2026, 09:08 AM
Package URL
pkg:socket/skills-sh/guia-matthieu%2Fclawfu-skills%2Frlm%2F@5ff7cc0dfceb77bfc325010765d5d3d66e0181df