publish-skill

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow is broadly aligned with publishing skills, but it includes a transitive remote install step via `npx skills add` that fetches and installs skill content from an external registry/CLI, plus repo push/cherry-pick actions with real impact. Because the installer appears official and documented, this is not strong evidence of malware; the main concern is supply-chain and transitive trust risk disproportionate to a simple publish helper.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 2, 2026, 02:17 PM
Package URL
pkg:socket/skills-sh/camacho%2Fai-skills%2Fpublish-skill%2F@673a440c3fd0f73e5b2264a51813b12d9483b31a