learn

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core behavior fits its stated purpose of learning a codebase, and its network flow goes directly to GitHub via standard tooling. The main risk is that it fetches and analyzes arbitrary untrusted repositories while parallel agents can write local files, creating a meaningful indirect prompt-injection and external-content handling risk; install trust is otherwise moderate and there is no clear credential harvesting or exfiltration path.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:19 AM
Package URL
pkg:socket/skills-sh/Soul-Brews-Studio%2Farra-oracle-skills%2Flearn%2F@85795512cc38ae1f717594ee63fb4204a8bcc278