tapestry

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches its extraction-and-planning behavior, and its explicit install path is mostly consistent with legitimate tooling. The main concern is scope: it fetches arbitrary external content and uses Bash plus file-writing to automatically generate outputs, creating medium indirect prompt-injection risk. No credential harvesting, covert exfiltration, or clearly malicious data routing is present.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/nicepkg%2Fai-workflow%2Ftapestry%2F@2029f920592c4fed432fabfcb2850e16360e9bfb