agent-skill-discovery
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill presents a coherent, benign Discovery-only tool that inventories installed resources and current repository assets across multiple AI CLI platforms. Its footprint remains read-only, with no credential handling, no unverified binaries, and no data exfiltration. The guidance consistently emphasizes dynamic discovery, platform-agnostic outputs, and separation of installed vs. local resources. Overall risk is low, with potential minor network considerations only if MCP tool enumeration introduces live lookups; this should be clearly documented as optional and controlled. The approach is appropriate for its stated purpose and proportionate to the task.
Confidence: 98%
Audit Metadata