prompt-engineering
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is legitimate and mostly aligned with the examples, but the skill’s footprint is broader than a simple prompt-engineering guide. It requires a vendor CLI login, routes prompt data through inference.sh to third-party model providers, grants wildcard `infsh` shell access, and encourages transitive installation of additional skills. This is not confirmed malware, but it carries medium risk due to broad execution scope and expanding trust boundaries.
Confidence: 87%Severity: 58%
Audit Metadata