find-skills

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its behavior, but that behavior is inherently high-trust because it installs other skills. Same-org CLI provenance reduces malware concern, yet the transitive installation model, unpinned `npx` execution, broad third-party git source support, global installs, and default telemetry make this a medium-high security risk.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Apr 23, 2026, 08:31 PM
Package URL
pkg:socket/skills-sh/citypaul%2F.dotfiles%2Ffind-skills%2F@ddd8b0f13b0e32d44db7fcb49e2120ad9c8861f6