cafe3310-skill-installer
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose matches its behavior, but it is a transitive installer that clones and executes mutable shell code from a personal GitHub repo without pinning or release verification, then installs additional skills into the agent environment. No clear credential theft or exfiltration is present, so this is not malicious, but the trust and transitive-install footprint make it medium/high risk.
Confidence: 92%Severity: 74%
Audit Metadata