tiangolo-library-skills

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the behavior, but the skill materially expands agent trust by loading third-party library skills from dependencies and a registry into active skill directories. Main concerns are transitive skill installation and indirect prompt injection, not overt credential theft or malware.

Confidence: 82%Severity: 71%
Audit Metadata
Analyzed At
May 2, 2026, 07:41 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Ftiangolo-library-skills%2F@b409fce257b72f6c3825a0f7e76c8579c23fc2c2