find-skills
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated purpose matches its behavior, and it uses an official documented CLI, so it is not overtly malicious. However, its core function is to discover and install third-party skills from GitHub or other sources, creating a transitive trust risk amplified by auto-confirmed installs and limited security verification.
Confidence: 91%Severity: 76%
Audit Metadata