journey-builder

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core journey-building behavior is plausible, but the mandatory hard-coded gist fetch introduces high indirect prompt-injection risk, and the skill also exfiltrates troubleshooting content back to GitHub via gist edits. Official tooling lowers supply-chain concern, yet the external content dependency and broad autonomous write/commit scope make the skill higher-risk than its stated purpose requires.

Confidence: 89%Severity: 77%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/sunfmin%2Fautocraft%2Fjourney-builder%2F@cd0080e936870c8801e30540b2e7184727892aa1