find-skills-combo

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is broadly coherent with its stated purpose of decomposing complex tasks and recommending multi-skill strategies. It aligns with typical agent orchestration patterns and uses standard registry-based installs. However, there are notable concerns around data flow transparency, potential credential exposure in metadata, and the possibility of automatic installations without explicit user approval. Given these concerns, classify as SUSPICIOUS rather than BENIGN until concrete safeguards (prompted confirmations, explicit permissioning for installations, and explicit data-handling policies) are described and enforced. Overall, the tool seems purpose-aligned but with moderate security risk due to orchestration of multiple external installs and potential data surfaces in metadata and workflow planning.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 02:58 AM
Package URL
pkg:socket/skills-sh/agentscope-ai%2Fopenjudge%2Ffind-skills-combo%2F@e47381ce0b88a09ca05641e5a3eca56adc541699