find-skills
Fail
Audited by Socket on Mar 1, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The skill is coherent with its stated purpose of helping users discover and install agent skills. It appropriately centers user-driven searches and explicit installation steps, leveraging established ecosystem tooling. There are no credential reads/writes or covert data flows within the fragment; the primary risk is the standard transitive risk inherent in installing third-party skills, which is mitigated by user consent and reliance on official registries. Overall, the footprint is benign and proportional to its purpose, with moderate transitive risk due to third-party skill installations.
Confidence: 95%Severity: 90%
Audit Metadata