skill-adapter

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose mostly matches local plugin analysis, but the actual footprint is broader than necessary. The main risk is not malware or exfiltration; it is indirect prompt injection and overbroad execution authority: the skill reads arbitrary plugin instructions/scripts, then adapts and applies them with unrestricted Bash access. No external install or credential flow was found, so this is not confirmed malicious, but it is a high-risk meta-skill that can propagate unsafe behaviors from untrusted repository content into real actions.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:36 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fskill-adapter%2F@71a96a2f49146e9572075b8c98c249ca608da588