find-best-skill

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated comparison purpose, but it has a higher-than-normal trust footprint because it fetches arbitrary remote SKILL.md content and can run side-by-side subagents from those instructions. There is no clear malware behavior, credential harvesting, or off-platform exfiltration, but the combination of remote instruction ingestion, Agent execution, and Bash/WebFetch access makes it medium risk.

Confidence: 86%Severity: 63%
Audit Metadata
Analyzed At
Apr 12, 2026, 06:37 AM
Package URL
pkg:socket/skills-sh/instantX-research%2Fskills%2Ffind-best-skill%2F@41925e9d922eb68ecf64e6e58a519f49b120f963