skill-management

Warn

Audited by Socket on Feb 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/pipeline.ts

This pipeline is functional for discovering and evaluating skills from GitHub but introduces supply-chain and data-handling risks due to cloning and copying external content without validation, and auto-selecting in non-interactive mode. To improve security, implement trust boundaries, validate repository contents before installation, sandbox downstream scripts, and sign or verify installed skills. No direct malware indicators detected in this fragment, but the risk profile remains medium due to external content handling.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Feb 17, 2026, 05:43 PM
Package URL
pkg:socket/skills-sh/dwsy%2Fagent%2Fskill-management%2F@3beee44296620a9aa919c249940108e523bf80c0