find-skills

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the fragment is coherently aligned with its stated purpose of helping users find and install agent skills. It relies on standard, community-driven tooling (npx skills) and public endpoints for discovery. The primary security concern is the inherent risk in executing external installs from public sources, which is a known ecosystem risk rather than an intrinsic flaw in this skill. No credential harvesting, data exfiltration, or autonomous real-world actions are evident in the fragment itself.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 08:06 PM
Package URL
pkg:socket/skills-sh/Brite-Nites%2Fbritenites-claude-plugins%2Ffind-skills%2F@b4d756260df587e8d599cb10a0cdb7fdb3c8d205