skill-installer

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the installer is internally consistent and uses official GitHub/OpenAI sources for curated content, but its main function is high-risk transitive skill installation. The largest concern is allowing arbitrary GitHub repos/private repos to place new skill instructions into the agent's trusted skill directory, not direct credential theft or off-platform exfiltration.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/firecrawl%2Fskills%2Fskill-installer%2F@cdedaa07a81fcfebe1a6d3630f66fd08dc247cbd