content-repurposing
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The skill is mostly coherent with its stated content-repurposing purpose and uses an officially documented same-org CLI, so it is not malware. Risk is driven by the pipe-to-shell installer, public posting capability, broad Bash-based execution model, and transitive installation of other skills. Overall classification: SUSPICIOUS due to medium trust and autonomy concerns, not due to clear malicious behavior.
Confidence: 87%Severity: 56%
Audit Metadata