benchmark-testing
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated purpose is benchmarking plugin injection, and its actual footprint matches that purpose, but the mechanism is high risk: it installs a remote plugin, enables it across many projects, and launches multiple agent sessions with crafted prompts that may trigger external actions. The main concern is transitive plugin installation and automated agent execution, not confirmed malware.
Confidence: 85%Severity: 72%
Audit Metadata