sync-global-rules

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s stated purpose matches its capabilities, and its only declared external service is GitHub via the official gh CLI. The main risk is supply-chain and persistence: it imports mutable content from a personal repository directly into global AI-agent rule files for two tools, giving upstream text durable influence over future agent behavior. This is better classified as suspicious/high-vulnerability potential rather than confirmed malware.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:54 AM
Package URL
pkg:socket/skills-sh/nangongwentian-fe%2Fagent-skills%2Fsync-global-rules%2F@4da043cc04dca5627d8d9bd9e4aa35cbb21ccd35