skill-auditor

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is mostly coherent with its stated purpose as a skill auditor: cloning repos, scanning files, reading content, and producing a report are expected. The main concerns are the unnecessary `git fetch/pull` step against the current repo, exposure to indirect prompt injection from untrusted skill contents, and its built-in ability to install another skill after analysis. Overall: suspicious-but-plausible, with medium risk rather than overtly malicious behavior.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 7, 2026, 06:38 PM
Package URL
pkg:socket/skills-sh/montimage%2Fskills%2Fskill-auditor%2F@1449a3c57f0637f96b74d32d8e16463ab4cb51ed