lyft-engineer

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
references/5-platform-support.md

Best report is Report 3’s framing: while no executable malware appears in the snippet itself, it operationalizes a supply-chain/prompt-injection pathway by pulling remote SKILL.md and persisting its contents into system prompts/custom rules for multiple developer/agent tools without integrity verification. Risk is therefore primarily about untrusted instruction persistence; review/pin the remote content (hash/signature) before applying and treat it as untrusted until verified.

Confidence: 66%Severity: 62%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:25 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Flyft-engineer%2F@feba2f657c09422d5474fe107d3f027365fcd76e