skillshare

Fail

Audited by Socket on Apr 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The documented behavior is coherent for a skill-management tool, but its footprint is inherently high risk because it installs and propagates third-party AI skills from arbitrary Git hosts, including with audit-bypass options. The main concern is transitive trust and prompt-injection risk from external skill content, not confirmed malware in this skill itself.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:52 AM
Package URL
pkg:socket/skills-sh/hubeiqiao%2Fskills%2Fskillshare%2F@3f39e8485393707c506663dc55bc696f8d3dba80