inflight

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the visible skill is thin and defers its real behavior to remote, mutable instructions. The source is same-org and therefore not strongly malicious on its face, but the runtime fetch-and-follow pattern weakens reviewability and introduces indirect prompt-injection and supply-chain trust risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/inflightsoftware%2Fskills%2Finflight%2F@31327b4e07ff5f4d20e9f6681c6d8a1174d3f4bc