magician

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly a benign persona/instruction pack for entertainment, but it is internally inconsistent due to unrelated business workflow content and it promotes transitive installation into other agent rule files. The main security concern is the unverifiable, unspecified remote [URL] inserted into persistent agent instructions, which creates medium supply-chain and prompt-injection risk even though there is no credential access, malware payload, or direct exfiltration behavior.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:25 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Fmagician%2F@65b59775f21fffddc48baed8a900c45fd9ef1210