find-skills
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s stated purpose matches its behavior, but that behavior is inherently high-trust because it installs other skills. Same-org CLI provenance reduces malware concern, yet the transitive installation model, unpinned `npx` execution, broad third-party git source support, global installs, and default telemetry make this a medium-high security risk.
Confidence: 90%Severity: 74%
Audit Metadata