skills-dev

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Detected system prompt override attempt All findings: [CRITICAL] prompt_injection: Detected system prompt override attempt (PI004) [AITech 1.1] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] Benign. The fragment is a self-consistent, well-structured specification/documentation piece intended to guide the creation and validation of Agent Skill definitions (SKILL.md). No executable code, credential handling, or external data flows are present. The footprint matches its stated purpose as a standards/guidance document rather than a functional tool or library.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:28 PM
Package URL
pkg:socket/skills-sh/outfitter-dev%2Fagents%2Fskills-dev%2F@9e337cc8042d76a4dcec839891512a508bdfb5b9