groove-admin-install

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s local setup behavior is broadly consistent with its stated bootstrap purpose, but it materially expands trust by installing multiple external skills through `npx skills add`, including third-party GitHub sources. There is no clear credential theft or exfiltration, so this is not malicious, but the transitive install and supply-chain footprint make it medium/high risk.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 23, 2026, 09:07 AM
Package URL
pkg:socket/skills-sh/andreadellacorte%2Fgroove%2Fgroove-admin-install%2F@efcd71c09b518b07cf943e03a92d794db099f971