cafe3310-skill-installer

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches its behavior, but it is a transitive installer that clones and executes mutable shell code from a personal GitHub repo without pinning or release verification, then installs additional skills into the agent environment. No clear credential theft or exfiltration is present, so this is not malicious, but the trust and transitive-install footprint make it medium/high risk.

Confidence: 92%Severity: 74%
Audit Metadata
Analyzed At
Apr 18, 2026, 05:33 AM
Package URL
pkg:socket/skills-sh/cafe3310%2Fpublic-agent-skills%2Fcafe3310-skill-installer%2F@68578bb55d24d2bd8f5e8dcc84e6874d42891523