kw-update-skills
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the capability, but the skill exists to update/install other remote skills, creating a transitive trust and supply-chain risk disproportionate to a simple helper. No clear credential theft or covert exfiltration is shown, but enabling bulk remote skill updates is materially risky.
Confidence: 88%Severity: 74%
Audit Metadata