prompt-engineer

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
evals/analyze-prompt.json

This JSON is a non-executable control/instruction object for a prompt-analysis agent. It does not contain direct malware (no network addresses, hardcoded creds, or destructive commands) but prescribes high-risk operations (chain-of-thought requests and model-class elicitation) that can lead to privacy leakage, model fingerprinting, and exposure of internal rationales if executed in a privileged or networked environment. Mitigations: treat as untrusted, block or sanitize 'Think step by step' requests, disable or sandbox model-class detection, avoid logging internal reasoning, and run analysis in a least-privilege, isolated environment. Overall: not malware, but a medium security risk depending on execution context.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/wyattowalsh%2Fagents%2Fprompt-engineer%2F@5c918075ac7699250b0585f80737b771ea4a8427