open-prose

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent with its orchestration purpose and no direct credential-exfiltration behavior, but it expands trust to arbitrary git-hosted dependencies and transitive contract execution. The autonomy-abuse finding appears overstated; the main risk is moderate supply-chain and transitive trust, not confirmed malware.

Confidence: 84%Severity: 54%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:38 AM
Package URL
pkg:socket/skills-sh/openprose%2Fprose%2Fopen-prose%2F@5ab5ce0ec17575921e38a885258c37a30636dbe5ff952e0c1fefe7f69389bd51
Security Audit — socket — open-prose