find-skills

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill fragment is internally consistent with its stated purpose of helping users discover and install open agent skills. It references legitimate workflows (npx skills find/add) and points to an external registry (skills.sh). There are no credential exposures, no embedded malware, and no suspicious data exfiltration patterns within the fragment itself. The primary supply-chain risk is the usual risk inherent in installing external skills (trust in sources, potential supply-chain risk of installed skills). Overall risk is ongoing but not inherently malicious in this fragment; treat as SUSPICIOUS/LOW-MED relative to supply-chain risk due to external installs, but not malicious by itself.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 11:37 PM
Package URL
pkg:socket/skills-sh/Im5tu%2Fclaude%2Ffind-skills%2F@a3b197ec9c78a32c79b21d5679a5d8721daff485