publish-skill

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose, but its purpose itself includes high-trust actions: running a third-party CLI via npx, publishing to GitHub, and instructing transitive installation of another skill. No clear credential theft or hidden exfiltration is present, so this is not malicious, but it carries meaningful supply-chain and autonomous-action risk.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Mar 20, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/acedergren%2Fagentic-tools%2Fpublish-skill%2F@8fdac475230592a1b474933a25005f1ed74b512b