use-findskill

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its behavior, but that behavior is high-risk because it teaches the agent to install and trust additional third-party skills. npm-based installation is more legitimate than raw download-execute, yet unpinned package execution, community/unverified skill content, and the `FINDSKILL_API` override create a significant transitive supply-chain and prompt-injection risk.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:49 PM
Package URL
pkg:socket/skills-sh/alentodorov%2Ffindskill-meta-skill%2Fuse-findskill%2F@c1f96e0d0e132044a9141b2a365582632ed376a7