manage-my-skills

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches skill management, but the footprint includes mandatory transitive skill installation through an unpinned third-party CLI and automatic push/install across multiple agents. This is not confirmed malware, but it carries medium-high supply-chain and trust-chain risk disproportionate to a simple local skill editor.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 05:11 AM
Package URL
pkg:socket/skills-sh/Derek-X-Wang%2Fskills%2Fmanage-my-skills%2F@9ad7627348bfa3de6e63e5bbc14bb661826d6d3f