benchmark-testing

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated benchmark purpose partly matches its behavior, but its main mechanism is an unverified plugin install plus transitive plugin enablement and automated agent launches designed to trigger injection behavior. The largest concern is install trust and inherited permissions from the added plugin, not confirmed malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 17, 2026, 09:25 AM
Package URL
pkg:socket/skills-sh/vercel%2Fvercel-plugin%2Fbenchmark-testing%2F@9c64efced1a78761b8be7f5b95096eb6d73329b2