groove-admin-install
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s local setup behavior is broadly consistent with its stated bootstrap purpose, but it materially expands trust by installing multiple external skills through `npx skills add`, including third-party GitHub sources. There is no clear credential theft or exfiltration, so this is not malicious, but the transitive install and supply-chain footprint make it medium/high risk.
Confidence: 86%Severity: 72%
Audit Metadata