skill-share

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The workflow correctly implements the stated goal of generating Xiaohongshu-ready content and adds an optional deep-analysis path that installs and inspects third-party 'skills'. The primary security concern is the auto-install and copy behavior: running npx to fetch/run third-party code and copying its files into agent runtime areas constitute a real supply-chain and remote code execution risk. The many user confirmation points help, but are insufficient without integrity checks, sandboxing, provenance verification, and audit-preserving behavior. Recommend treating auto-install as high privilege: require explicit user acknowledgement, add package signature/checksum verification, prefer manual installs or isolated sandboxed environments, preserve installer artifacts for auditing, and avoid automatic copying of executable content into runtime areas.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 19, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/ing-la%2Fagent-skills-share%2Fskill-share%2F@1c2e0cdd9270f7164e26644118e3725ea504c96f