skill-seekers-ref

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated purpose, but it has a broad footprint: it ingests untrusted external content, may use API credentials, and can package/upload/install generated skills into agent environments. The main concern is indirect prompt injection and propagation of untrusted content into skills; install provenance for the CLI itself is also unverified from the provided evidence.

Confidence: 79%Severity: 66%
Audit Metadata
Analyzed At
Apr 3, 2026, 07:13 PM
Package URL
pkg:socket/skills-sh/tenequm%2Fskills%2Fskill-seekers-ref%2F@275fa69d004c479d896da60b7c7d585a112f749d