knowledge-absorber

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but its footprint is broader than ideal. The main issues are automatic dependency installation from an unseen requirements file and prompt-injection risk from ingesting untrusted external content, web-auditing it, and then writing outputs. No clear credential theft or exfiltration is shown, so this is not confirmed malware.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
Mar 17, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/YuJunZhiXue%2FStudyAnalysis-Skills%2Fknowledge-absorber%2F@62d6453756a18d94ae337178348239259b1fc7d0