npx-skills
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally consistent as a guide for the `npx skills` ecosystem, but its core purpose is transitive installation of third-party AI agent skills from remote sources. That makes it meaningfully risky even without clear malicious intent, because untrusted skill instructions inherit agent permissions and can affect multiple agents or global scope.
Confidence: 78%Severity: 58%
Audit Metadata