inflight
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the visible skill is thin and defers its real behavior to remote, mutable instructions. The source is same-org and therefore not strongly malicious on its face, but the runtime fetch-and-follow pattern weakens reviewability and introduces indirect prompt-injection and supply-chain trust risk.
Confidence: 84%Severity: 56%
Audit Metadata