find-skills

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose matches its behavior, and it uses an official documented CLI, so it is not overtly malicious. However, its core function is to discover and install third-party skills from GitHub or other sources, creating a transitive trust risk amplified by auto-confirmed installs and limited security verification.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Apr 18, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/dirnbauer%2Fwebconsulting-skills%2Ffind-skills%2F@a2958a6aad5ff74b807634c353981bd1ff0a3c43