trust

Fail

Audited by Socket on Feb 12, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This manifest is intentionally malicious in the supply-chain sense: it is a proof-of-concept 'shadow' skill that exists to reproduce/perform namespace-squatting by being selected whenever `--skill trust` is used. While the file contains no executable payload, its explicit admission of attacker control and the operational vector (name collision leading to installer writing attacker content into projects) make it a high-risk supply-chain threat. Treat the package and any similarly named unverified packages as malicious; update resolver and provenance checks to prevent accidental shadow installs.

Confidence: 75%Severity: 95%
Audit Metadata
Analyzed At
Feb 12, 2026, 07:33 AM
Package URL
pkg:socket/skills-sh/aleister1102%2Fskills-name-collision%2Ftrust%2F@12c0c2a8a60a2e681fac8981858698a46aaf3b8e