skill-management

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/pipeline.ts

This pipeline is functional for discovering and evaluating skills from GitHub but introduces supply-chain and data-handling risks due to cloning and copying external content without validation, and auto-selecting in non-interactive mode. To improve security, implement trust boundaries, validate repository contents before installation, sandbox downstream scripts, and sign or verify installed skills. No direct malware indicators detected in this fragment, but the risk profile remains medium due to external content handling.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:29 PM
Package URL
pkg:socket/skills-sh/dwsy%2Fagent%2Fskill-management%2F@3beee44296620a9aa919c249940108e523bf80c0