prompt-engineering

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is legitimate and mostly aligned with the examples, but the skill’s footprint is broader than a simple prompt-engineering guide. It requires a vendor CLI login, routes prompt data through inference.sh to third-party model providers, grants wildcard `infsh` shell access, and encourages transitive installation of additional skills. This is not confirmed malware, but it carries medium risk due to broad execution scope and expanding trust boundaries.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:49 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills%2Fprompt-engineering%2F@2de8ef55bf885f04cd51b2318f2533aecd60a7b1