find-skills

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能目的与能力基本一致,官方 CLI 来源也可验证,因此不像伪装型恶意技能;但其核心行为是为代理安装第三方技能,带来明显的转移信任与供应链风险。整体应判为 SUSPICIOUS:不是确认恶意,但风险高于普通文档/工具技能。

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Apr 12, 2026, 05:57 AM
Package URL
pkg:socket/skills-sh/43COLLEGE%2F43-Agent-skills%2Ffind-skills%2F@eebaaf74f992813d20fe9e06ad8bd889d4b0458e