evolve

Warn

Audited by Socket on Apr 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
skill-creator/SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it instructs the agent to install/load other skills from personal GitHub marketplaces and to ingest untrusted web/GitHub content while generating executable guidance and publishing outputs. The main issues are transitive skill trust and indirect prompt-injection exposure, not confirmed malware.

Confidence: 84%Severity: 61%
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s broad autonomous behavior is consistent with its stated self-evolving purpose, but that purpose is itself high-scope. The main risk is autonomy plus unspecified version-check/auto-update behavior whose trust path is not visible here; there is no clear evidence of credential theft, third-party interception, or confirmed malware in the provided excerpt.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:15 PM
Package URL
pkg:socket/skills-sh/miles990%2Fevolve-plugin%2Fevolve%2F@3310177549e2c16fa53fb2618f40b510a5fcb509