compound-engineering-3

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose mostly aligns with its file-writing and scheduling behavior, but it introduces meaningful risk through autonomous review of prior agent outputs, persistent modification of instruction/memory files, and automated git actions. No clear credential theft or third-party exfiltration is shown, so this is not confirmed malware; the main concerns are supply-chain trust for the referenced npm package and indirect prompt-injection/self-modification risk.

Confidence: 78%Severity: 61%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:26 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fcompound-engineering-3%2F@8c0cc14f6ef924f38785f55ddfd0c52dcc0f7249