tiangolo-library-skills
Warn
Audited by Socket on May 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the behavior, but the skill materially expands agent trust by loading third-party library skills from dependencies and a registry into active skill directories. Main concerns are transitive skill installation and indirect prompt injection, not overt credential theft or malware.
Confidence: 82%Severity: 71%
Audit Metadata