npx-skills

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally consistent as a guide for the `npx skills` ecosystem, but its core purpose is transitive installation of third-party AI agent skills from remote sources. That makes it meaningfully risky even without clear malicious intent, because untrusted skill instructions inherit agent permissions and can affect multiple agents or global scope.

Confidence: 78%Severity: 58%
Audit Metadata
Analyzed At
Apr 8, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/dagster-io%2Ferk%2Fnpx-skills%2F@6dc9b02c63d38a4276206fb2ec48ba155ac3f962