activation
Warn
Audited by Socket on Apr 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated purpose is activation/orchestration, but its actual footprint imposes mandatory pre-response skill execution, local file loading fallback, and broad transitive trust in any installed skill. It is not confirmed malware, but it meaningfully increases prompt-injection and autonomy risk by forcing external instruction ingestion before normal conversation handling.
Confidence: 90%Severity: 72%
Audit Metadata