lesson

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose is coherent (capture and persist lessons to MEMORY.md). However, the installation approach introduces a high-severity supply-chain risk due to downloading and executing a remote script from raw GitHub content. This creates an uncontrollable code path that could alter behavior, access system resources, or exfiltrate data. While the local MEMORY.md writing aligns with the purpose, the install source undermines trust and warrants remediation (use an official registry, pinned version, and checksum verification). Overall, the capability is suspicious but not proven malicious; treat as SUSPICIOUS with strong security mitigations recommended before deployment.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 8, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/Ai-feier%2Fskills%2Flesson%2F@c20752102adaed25372184ce26db837404cecce6