template-remove
Fail
Audited by Socket on Mar 4, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The package manifest performs a legitimate maintenance operation (removing a template and unregistering it). The principal supply-chain concern is execution of an opaque PowerShell script with broad filesystem permissions and no documented safeguards. Before running this skill in production, review the script's contents, verify it limits operations to the declared SrcDir and XML edits, add or perform backups, and run with least privilege. If the script cannot be inspected or if it performs network operations, consider rejecting or sandboxing execution.
Confidence: 98%
Audit Metadata