benchmark-testing

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose is benchmarking plugin injection, and its actual footprint matches that purpose, but the mechanism is high risk: it installs a remote plugin, enables it across many projects, and launches multiple agent sessions with crafted prompts that may trigger external actions. The main concern is transitive plugin installation and automated agent execution, not confirmed malware.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Mar 16, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fvercel-plugin%2Fbenchmark-testing%2F@9c64efced1a78761b8be7f5b95096eb6d73329b2