skill-curator
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileThe Skill Curator concept is broadly benign and aligns with a legitimate workflow for maintaining a centralized skill catalog by extracting standardized metadata from SKILL.md files. It emphasizes discovering SKILL.md files, extracting frontmatter, categorizing, and updating a README. The footprint remains largely read/transform operations on public repository content and local README updates, with no explicit credential handling or remote data exfiltration. Potential concerns include handling of private repositories, lack of explicit verification of SKILL.md integrity, and absence of rollback/audit mechanisms for changes. Overall, the footprint is proportionate to the stated purpose, with minor security/vaulting gaps that are addressable by clarifying access controls and adding basic logging.