sophnet-skill-installer

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns with its stated purpose of discovering and installing Sophnet skills from a default GitHub repo with a fallback, and it includes version comparison logic. However, there are notable security concerns: transitive installations from unverified external repos, optional but potentially risky handling of GitHub tokens, and the use of scripts that download and write to the workspace which could be manipulated if inputs are not strictly validated. The data flows depend on external sources (GitHub APIs) and credentials could be exposed through logs or environment variables. Overall, the footprint is SUSPICIOUS rather than clearly BENIGN, due to supply-chain and credential-exposure risks inherent in remote installs and multi-source behavior. Recommend tightening: restrict to verified repositories, enforce strict input validation, avoid logging sensitive tokens, and consider pinning skill sources with checksums/signatures.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 08:09 AM
Package URL
pkg:socket/skills-sh/DuffyCoder%2Fawesome-sophnet-skills%2Fsophnet-skill-installer%2F@979e2f993440d79fc177fdd6cdb2c79e8983c10c