discover-a-skill

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This SKILL.md is a benign-looking manifest describing how the askill agent should discover, install and run skills. However, its install and execution model creates a moderate-to-high supply-chain and privilege-risk: it allows installing and automatically running code from arbitrary GitHub repos and other sources, references local credentials and lock files, and encourages automated (-y) non-interactive installs and setup runs. The document itself contains no direct malicious code or obfuscation, but it defines a workflow that could be abused to harvest credentials or execute malicious payloads via third‑party skills. Recommend treating installs from untrusted sources as high risk: require pinned commits, signatures, manual approval, and limit access to credentials and network capabilities for installed skills.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:39 AM
Package URL
pkg:socket/skills-sh/avibe-bot%2Faskill%2Fdiscover-a-skill%2F@e7b1661699901b5cdb485bc697d65463c1ec69d2