find-skills

Warn

Audited by Socket on Apr 12, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/hiclaw-find-skill.sh

This wrapper’s own logic appears to be a legitimate orchestration and ranking tool: it primarily calls external CLIs, parses their output, and prints install hints. However, it introduces meaningful supply-chain/operational risk by executing a runtime dependency via `npx -y @nacos-group/cli` (un-pinned runtime fetch/execute) and it forwards Nacos secrets to that subprocess via command-line flags (potential exposure through process listings/logs). No explicit malware/payload behavior is present in this snippet, but the risk profile is elevated due to runtime npm execution and credential handling practices.

Confidence: 63%Severity: 57%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches discovery/install, but the actual footprint is a high-risk transitive installer using a custom wrapper and registry path with unclear provenance. The main concern is not immediate malware but broad supply-chain and inherited-permission risk from installing unreviewed third-party skills.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Apr 12, 2026, 11:10 AM
Package URL
pkg:socket/skills-sh/agentscope-ai%2FHiClaw%2Ffind-skills%2F@a5285f5b6b93a043861519be5c10badc8ec48a75