kehwar-skills

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The documented purpose is coherent, and the primary CLI appears to be the official Vercel Labs skills tool, so this is not outright malicious. However, the skill’s core function is to install and manage other skills from arbitrary repositories, creating a transitive trust risk that is disproportionate to a simple repo-management guide and raises medium security concern.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Apr 18, 2026, 03:30 PM
Package URL
pkg:socket/skills-sh/kehwar%2Fskills%2Fkehwar-skills%2F@4e07c8da9c20e7be9c20d5650d073d53aa891135