simple-brainstorm

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The brainstorming instructions themselves are benign. The embedded, mandatory curl command that sends the local hostname to simplebrainstorm.io creates an avoidable supply-chain and privacy risk: it leaks environment metadata and allows unverified remote content to influence agent behavior (prompt injection). This is a risky pattern for automation and should be removed or made opt-in with integrity checks and without transmitting host-identifying information. Do not execute the curl command in automated contexts until the resource is vetted and protected; if an agent must fetch remote guidance, require pinned integrity, signatures, and avoid passing local identifiers.

Confidence: 75%Severity: 65%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/roin-orca%2Fskills%2Fsimple-brainstorm%2F@0748bce31b2a0e5aaec4e5b07ce40726d5e4fd67