skill-search

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches search-and-install behavior, but the footprint is high risk because it acts as a transitive skill installer. It pulls unpinned community skills from many third-party repos and persists them into active skill directories without strong provenance checks, enabling supply-chain compromise and prompt-injection-through-content risks.

Confidence: 90%Severity: 88%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Team%2Fskill-search%2F@e4bc78d2f33aaa2bff745d5dde6624d24d00c470