prism-ade

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Prism ADE skill description is largely coherent with its stated purpose of documenting and guiding a multi-agent document extraction workflow. There are no obvious supply-chain download/execution patterns, no explicit credential harvesting, and no autonomous real-world actions described. The data flows are internal to the Prism stack and OpenAI API usage, aligning with a development/tooling/documentation focus rather than external data exfiltration. Given the absence of risky patterns, the overall footprint is benign with respect to security threat models; however, consider adding explicit privacy controls, secret management details, and confirmation of secure data handling practices to strengthen security posture.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:52 AM
Package URL
pkg:socket/skills-sh/SivaG-lab%2Froth_mcp%2Fprism-ade%2F@0b3dbea42ee85fd52abfc3a37467edade7ea3459