amd

Warn

Audited by Socket on Mar 25, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is a benign AMD persona skill, and its capabilities are mostly just prompt instructions with no credential access or direct exfiltration. However, the installation method is not proportionate to a simple persona skill: it appends a mutable raw GitHub URL from an unverified personal repo into Claude's persistent instruction file, creating a transitive trust and prompt-supply-chain risk. No evidence of credential theft or malware payloads was provided, so this is not malicious, but it is riskier than a normal static documentation skill.

Confidence: 90%Severity: 59%
AnomalyLOW
amd-engineer/SKILL.md

SUSPICIOUS: the skill’s stated purpose is benign and mostly documentation-only, but its install flow is not proportionate or well-aligned with normal skill distribution. The main risk is a persistent remote-instruction trust chain from an unverifiable third-party repo owner rather than malware or credential theft.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Famd%2F@607fde87157387efbadd61bcd1219b83f297ce44