skill-seekers-ref
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities mostly match its stated purpose, but it has a broad footprint: it ingests untrusted external content, may use API credentials, and can package/upload/install generated skills into agent environments. The main concern is indirect prompt injection and propagation of untrusted content into skills; install provenance for the CLI itself is also unverified from the provided evidence.
Confidence: 79%Severity: 66%
Audit Metadata