swain-update

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose matches its update behavior, and the main install path uses an official public CLI, but the overall footprint is still risky because it installs a full third-party skill bundle from a personal repo, uses wildcard selection, includes an unpinned git-clone fallback, and chains into another skill. This looks more like a high-trust updater than overt malware, but the transitive trust and local overwrite behavior make it medium-high risk.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 14, 2026, 01:49 PM
Package URL
pkg:socket/skills-sh/cristoslc%2Fswain%2Fswain-update%2F@4fe5e4b68c48a12569b56b0681f8eade6b84e3bc