find-skills-combo
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe skill's footprint is broadly coherent with its stated purpose of decomposing complex tasks and recommending multi-skill strategies. It aligns with typical agent orchestration patterns and uses standard registry-based installs. However, there are notable concerns around data flow transparency, potential credential exposure in metadata, and the possibility of automatic installations without explicit user approval. Given these concerns, classify as SUSPICIOUS rather than BENIGN until concrete safeguards (prompted confirmations, explicit permissioning for installations, and explicit data-handling policies) are described and enforced. Overall, the tool seems purpose-aligned but with moderate security risk due to orchestration of multiple external installs and potential data surfaces in metadata and workflow planning.