add-skill
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent, but the skill is inherently high-risk because it installs arbitrary third-party skills, creating a transitive trust chain and durable prompt/code execution surface beyond the wrapper's own scope.
Confidence: 93%Severity: 88%
Audit Metadata