marketingskills-ai-agents
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches its behavior, but its main function is transitive installation of a third-party skill pack from a personal GitHub repo using unpinned fetch methods. No credential theft or exfiltration is evident, so this is not malware, but it carries meaningful supply-chain and inherited-permission risk.
Confidence: 87%Severity: 72%
Audit Metadata