skill-updater

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and local file access are broadly coherent for skill maintenance, and the cited external endpoints are mostly official. The main concern is indirect prompt injection and trust expansion: it ingests external GitHub/Exa/arXiv content, can run Bash and edit files, and delegates to multiple other skills. Its explicit security scan, provenance logging, and confirmation gates reduce but do not eliminate that risk.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
Mar 23, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fskill-updater%2F@d6176cf251b645e2a2008372b9aa23e93167cf64