find-skills

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is not overtly malicious, and its CLI install path appears official and purpose-aligned. The main risk is inherent transitive trust: it exists to discover and install third-party skills that inherit agent permissions, so overall classification is suspicious/high-risk from a security standpoint despite low evidence of malicious intent in this skill itself.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:58 PM
Package URL
pkg:socket/skills-sh/acedergren%2Fagentic-tools%2Ffind-skills%2F@47f5f10d8f823caa6755fdbba57467428ea04ed9