agent-retro

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is locally scoped and has no external download or exfiltration path, but it reads broad prior conversations and persists derived guidance into USER.md, SOUL.md, AGENTS.md, and MEMORY.md without prior user approval. The main risk is prompt-injection persistence and unsafe autonomous self-modification, not malware.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Mar 25, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/Tangc%2Ftangzhan-skills%2Fagent-retro%2F@4a47b3ea37070d30a1040f2e485a9484af97c3b9