audit

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main behavior matches a code-audit utility, but its footprint is fairly powerful: multi-agent analysis of untrusted repository content, local command execution, automatic report commits, and optional task/issue creation. No clear credential theft or malicious exfiltration is present, but the combination of indirect prompt-injection exposure and autonomous repo modifications makes it medium risk.

Confidence: 86%Severity: 67%
Audit Metadata
Analyzed At
Mar 14, 2026, 05:49 AM
Package URL
pkg:socket/skills-sh/howells%2Farc%2Faudit%2F@13a55d774c79d80b9120987e790a1ee244d7b29c