open-prose
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: mostly coherent with its orchestration purpose and no direct credential-exfiltration behavior, but it expands trust to arbitrary git-hosted dependencies and transitive contract execution. The autonomy-abuse finding appears overstated; the main risk is moderate supply-chain and transitive trust, not confirmed malware.
Confidence: 84%Severity: 54%
Audit Metadata